WordPress Plugin Vulnerabilities

Simple History < 5.27.0 - Subscriber+ Account Takeover via Missing Authorization on Event Reaction Endpoint

Description

The plugin is vulnerable to account takeover via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_permissions_check() as their permission_callback, which only verifies the requester is logged in and does not enforce the per-logger capability checks normally applied by Log_Query. As a result, a Subscriber-level user can POST to /wp-json/simple-history/v1/events/<id>/react with the _fields=context query parameter and read the full context of any logged event — including SimpleUserLogger entries that record the full password-reset email body (reset URL with the reset key) for any user. The attacker triggers a password reset for an administrator via the lost-password form, brute-forces recent event IDs through the reaction endpoint to read the resulting user_requested_password_reset_link event, extracts the reset key from context.message, and completes the password reset to take over the administrator account. Exploitation requires an administrator to have first enabled the experimental features option (simple_history_experimental_features_enabled), which is not the default.

Affects Plugins

Fixed in 5.27.0

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
lhking
Verified
No

Timeline

Publicly Published
2026-05-29 (about 2 months ago)
Added
2026-06-01 (about 2 months ago)
Last Updated
2026-06-01 (about 2 months ago)

Other