PT-2024-16713 · WordPress · Apppresser
Khayal Farzaliyev
+1
·
Published
2024-11-26
·
Updated
2024-11-26
·
CVE-2024-11024
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The AppPresser – Mobile App Framework plugin for WordPress versions up to, and including, 4.4.6
Description
The issue is related to privilege escalation via account takeover. This occurs because the plugin does not properly validate a user's password reset code before updating their password. As a result, unauthenticated attackers who know a user's email address can reset the user's password and gain access to their account.
Recommendations
For versions up to, and including, 4.4.6, update to a version that fixes the password reset validation issue to prevent account takeover.
As a temporary workaround, consider restricting access to the password reset functionality until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apppresser