Lucene search

K
wpvulndbWpvulndbWPVDB-ID:BDDA38EF-0F57-4585-8389-93A236BCEDE4
HistoryNov 23, 2023 - 12:00 a.m.

AppPresser < 4.3.0 - Insecure Password Reset Mechanism

2023-11-2300:00:00
wpscan.com
6
apppresser
wordpress
password reset
vulnerability
insecure mechanism

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.9%

Description The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.

CPENameOperatorVersion
eq4.3.0

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.9%

Related for WPVDB-ID:BDDA38EF-0F57-4585-8389-93A236BCEDE4