Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24527

Опубликовано: 16 авг. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Средний

Описание

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cozmoslabs:profile_builder:*:*:*:*:*:wordpress:*:*
Версия до 3.4.9 (исключая)

EPSS

Процентиль: 99%
0.69958
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
больше 3 лет назад

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.

EPSS

Процентиль: 99%
0.69958
Средний

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-287