PT-2024-39559 · WordPress · Apppresser

Wesley

·

Published

2024-10-15

·

Updated

2025-05-17

·

CVE-2024-9305

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The AppPresser – Mobile App Framework plugin for WordPress versions up to, and including, 4.4.4
Description The issue is related to privilege escalation via account takeover. This is due to the appp reset password() and validate reset password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users' passwords, including an administrator.
Recommendations For versions up to, and including, 4.4.4, consider disabling the appp reset password() and validate reset password() functions until a patch is available to prevent brute force attacks. Restrict access to password reset functionality to minimize the risk of exploitation. Avoid using the OTP for password reset until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Weakness Enumeration

Related Identifiers

CVE-2024-9305

Affected Products

Apppresser