Simple Membership <= 4.3.4 - Account Takeover via Password Reset

2023-09-25 00:00
Rafie Muhammad

Strategic Overview

Status
Patched in 4.3.5
Affected PluginSimple Membership
Affected Version<= 4.3.4
CVSS8.8High
CVECVE-2023-41956
View all Simple Membership vulnerabilities

Vulnerability Overview

The Simple Membership plugin for WordPress is vulnerable to account takeover due to missing input validation on the process_password_reset_using_link function in versions up to, and including, 4.3.4. This makes it possible for authenticated attackers to gain access to arbitrary accounts on the site via the password reset functionality.

Technical Analysis

REMEDIATION: Update to version 4.3.5, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C