WordPress Plugin Vulnerabilities

Advanced Forms < 1.6.9 - Subscriber+ Arbitrary User Email Address Update via IDOR

Description

Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To exploit this vulnerability, an attacker must register to obtain a valid WordPress's user and use such user to authenticate with WordPress in order to exploit the vulnerable edit function.

Proof of Concept

Affects Plugins

Fixed in 1.6.9
Fixed in 1.6.9

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
Suppawit Punhakit
Submitter
Suppawit Punhakit
Verified
Yes

Timeline

Publicly Published
2020-06-27 (about 5 years ago)
Added
2021-10-21 (about 4 years ago)
Last Updated
2022-04-11 (about 3 years ago)

Other