Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-2449
HistoryNov 22, 2023 - 4:15 p.m.

Sql injection

2023-11-2216:15:00
PRIOn knowledge base
www.prio-n.com
9
vulnerability
userpro plugin
wordpress
unauthorized password resets
insufficient validation
plaintext
hashed value
exploit
cve-2023-2448
cve-2023-2446
sql injection

6.5 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.2%

The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (userpro_process_form). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-2448 and CVE-2023-2446, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit this vulnerability.

CPENameOperatorVersion
userprole5.1.1

6.5 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.2%