AppPresser <= 4.2.5 - Insecure Password Reset Mechanism
2023-11-16 00:00
István MártonStrategic Overview
StatusPatched in 4.3.0
Affected PluginAppPresser – Mobile App Framework
Affected Version
<= 4.2.5CVSS8.1High
CVE
CVE-2023-4214Vulnerability Overview
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.
Technical Analysis
REMEDIATION: Update to version 4.3.0, or a newer patched version --- IDENTIFIER: CWE-620 (Unverified Password Change) When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C