Unauthenticated Attackers Can Reset User Passwords via Weak Password Reset Mechanism in Build App Online Plugin
CVE-2023-7264
8.1HIGH
Summary
The Build App Online plugin for WordPress presents a significant security risk due to a flaw in its password reset mechanism. All versions up to and including 1.0.21 are affected, allowing unauthenticated attackers to reset passwords for arbitrary user accounts by exploiting a weak numerical reset code comprised of just four digits. This vulnerability highlights the need for stronger authentication protocols and underscores the importance of securing user accounts against unauthorized access.
Affected Version(s)
Build App Online * <= 1.0.21
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ramuel Gall