Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9c9-gpm6-qqq6

Опубликовано: 29 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

EPSS

Процентиль: 2%
0.00014
Низкий

8.1 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.1
nvd
10 дней назад

The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

EPSS

Процентиль: 2%
0.00014
Низкий

8.1 High

CVSS3

Дефекты

CWE-269