PT-2023-15105 · WordPress · User Verification Wordpress Plugin
Lana Codes
·
Published
2023-01-23
·
Updated
2023-06-23
·
CVE-2022-4693
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
User Verification WordPress plugin versions prior to 1.0.94
Description
The issue allows for an authentication bypass, requiring only the knowledge of a user's username to exploit. Since usernames are often publicly available, an attacker may gain administrative access to a website by exploiting this issue.
Recommendations
For versions prior to 1.0.94, update to version 1.0.94 or later to resolve the authentication bypass issue. As a temporary workaround, consider restricting access to sensitive areas of the website that rely on user authentication until the update can be applied.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
User Verification Wordpress Plugin