Easy Digital Downloads 3.1 - 3.1.1.4.1 - Unauthenticated Arbitrary Password Reset to Privilege Escalation
Strategic Overview
3.1 – < 3.1.1.4.2CVE-2023-30869Vulnerability Overview
The Easy Digital Downloads plugin for WordPress is vulnerable to Unauthenticated Arbitrary Password Resets to Privilege Escalation in versions 3.1 to 3.1.1.4.1. This is due to a lack of validation of a password reset key in the edd_validate_password_reset function. This makes it possible for unauthenticated attackers to reset the password of any user on a vulnerable site, including an administrator, if they have the email or username of the targeted account.
Technical Analysis
REMEDIATION: Update to version 3.1.1.4.2, or a newer patched version --- IDENTIFIER: CWE-620 (Unverified Password Change) When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C