WordPress Plugin Vulnerabilities

AppPresser < 4.4.7 - Unauthenticated Privilege Escalation via Password Reset

Description

The plugin is vulnerable to privilege escalation via account takeover due to the plugin not properly validating a user's password reset code prior to updating their password. This makes it possible for unauthenticated attackers, with knowledge of a user's email address, to reset the user's password and gain access to their account.

Affects Plugins

Fixed in 4.4.7

References

Classification

Miscellaneous

Original Researcher
shaman0x01
Verified
No

Timeline

Publicly Published
2024-11-25 (about 1 year ago)
Added
2024-12-02 (about 1 year ago)
Last Updated
2024-12-02 (about 1 year ago)

Other