WordPress Plugin Vulnerabilities

Profile Builder < 3.4.9 - Admin Access via Password Reset

Description

The plugin has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.

Proof of Concept

Affects Plugins

Fixed in 3.4.9

References

Classification

Miscellaneous

Original Researcher
Stiofan
Submitter
Stiofan
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-07-19 (about 4 years ago)
Added
2021-07-19 (about 4 years ago)
Last Updated
2022-04-12 (about 3 years ago)

Other