Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ggm5-8542-75h6

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.

The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.

EPSS

Процентиль: 14%
0.00226
Низкий

8.1 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 месяцев назад

The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.

EPSS

Процентиль: 14%
0.00226
Низкий

8.1 High

CVSS3

Дефекты

CWE-287