Checkout Mestres WP <= 7.1.9.6 - Authentication Bypass via Password Reset

2023-12-27 00:00
Rafie Muhammad

Strategic Overview

Status
Patched in 7.1.9.8
Affected Version<= 7.1.9.6
CVSS9.8Critical
CVECVE-2023-51472
View all Checkout Mestres do WP for WooCommerce vulnerabilities

Vulnerability Overview

The Checkout Mestres WP plugin for WordPress is vulnerable to authentication due to a weak password reset functionality in all versions up to, and including, 7.1.9.6. This makes it possible for unauthenticated attackers to reset the password of arbitrary users to a guessable value based on the current time.

Technical Analysis

REMEDIATION: Update to version 7.1.9.8, or a newer patched version --- IDENTIFIER: CWE-640 (Weak Password Recovery Mechanism for Forgotten Password) The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C