Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hgq7-79qc-3jhq

Опубликовано: 02 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

EPSS

Процентиль: 2%
0.00015
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 9.8
nvd
7 дней назад

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

EPSS

Процентиль: 2%
0.00015
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269