Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-3793

Опубликовано: 24 апр. 2025
Источник: nvd
CVSS3: 4.2
EPSS Низкий

Описание

The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.

EPSS

Процентиль: 12%
0.00039
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-620

Связанные уязвимости

CVSS3: 4.2
github
10 месяцев назад

The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.

EPSS

Процентиль: 12%
0.00039
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-620