PT-2023-15105 · WordPress · User Verification Wordpress Plugin

·

CVE-2022-4693

·

Publicado

2023-01-23

·

Atualizado

2023-06-23

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions User Verification WordPress plugin versions prior to 1.0.94
Description The issue allows for an authentication bypass, requiring only the knowledge of a user's username to exploit. Since usernames are often publicly available, an attacker may gain administrative access to a website by exploiting this issue.
Recommendations For versions prior to 1.0.94, update to version 1.0.94 or later to resolve the authentication bypass issue. As a temporary workaround, consider restricting access to sensitive areas of the website that rely on user authentication until the update can be applied.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-4693

Produtos afetados

User Verification Wordpress Plugin