PT-2023-15105 · WordPress · User Verification Wordpress Plugin
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
User Verification WordPress plugin versions prior to 1.0.94
Description
The issue allows for an authentication bypass, requiring only the knowledge of a user's username to exploit. Since usernames are often publicly available, an attacker may gain administrative access to a website by exploiting this issue.
Recommendations
For versions prior to 1.0.94, update to version 1.0.94 or later to resolve the authentication bypass issue. As a temporary workaround, consider restricting access to sensitive areas of the website that rely on user authentication until the update can be applied.
Exploit
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
User Verification Wordpress Plugin