PT-2023-31069 · WordPress · Wp User Control

István Márton

+1

·

Published

2023-09-12

·

Updated

2023-09-15

·

CVE-2023-4915

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP User Control plugin for WordPress versions up to, and including 1.5.3
Description The issue arises from the plugin's use of native password reset functionality with insufficient validation on the password reset function in the WP User Control Widget. This function changes a user's password after providing their email, and the new password is sent to the user's email. As a result, an attacker can initiate unauthorized password resets but will not have access to the new password.
Recommendations For versions up to, and including 1.5.3, update to a version later than 1.5.3 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-4915

Affected Products

Wp User Control