YITH Easy Login & Register Popup for WooCommerce <= 1.8.0 - Authentication Bypass via Password Reset

2021-09-20 00:00
Anonymous

Strategic Overview

Status
Patched in 1.8.1
Affected Version<= 1.8.0
CVSS9.8Critical
CVECVE-2021-39331
View all YITH Easy Login & Register Popup for WooCommerce vulnerabilities

Vulnerability Overview

The YITH Easy Login & Register Popup for WooCommerce plugin for WordPress is vulnerable to authorization bypass via password reset in versions up to, and including, 1.8.0. This is due to the plugin failing to properly validate if a user is authorized to perform a password reset for the supplied user_login via the yith_welrp_form_action AJAX. This makes it possible for unauthenticated users to reset administrators password and then log in to a site using that account.

Technical Analysis

REMEDIATION: Update to version 1.8.1, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C