Description
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12926 | The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones. |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-26T19:05:40.403Z
Reserved: 2023-02-21T15:17:48.691Z
Link: CVE-2023-0940
Updated: 2024-08-02T05:32:45.037Z
Status : Modified
Published: 2023-03-20T16:15:12.950
Modified: 2025-02-26T19:15:16.033
Link: CVE-2023-0940
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD