User Verification <= 1.0.93 - Privilege Escalation
2022-12-28 00:00
István MártonStrategic Overview
StatusPatched in 1.0.94
Affected PluginUser Verification by PickPlugins
Affected Version
<= 1.0.93CVSS9.8Critical
CVE
CVE-2022-4693Vulnerability Overview
The User Verification plugin for WordPress is vulnerable to authentication bypass. This is due to the fact that when generating OTP codes for users to use in order to login, the plugin returns these codes in an AJAX response. This makes it possible for unauthenticated attackers to obtain login codes for administrators.
Technical Analysis
REMEDIATION: Update to version 1.0.94, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C