The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51158 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jan 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scriptsbundle
Scriptsbundle adforest |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:scriptsbundle:adforest:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Scriptsbundle
Scriptsbundle adforest |
Wed, 22 Jan 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unauthenticated attackers to authenticate as any user as long as they have configured OTP login by phone number. | |
| Title | AdForest <= 5.1.8 - Authentication Bypass | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-12T19:14:31.820Z
Reserved: 2024-12-20T16:29:31.692Z
Link: CVE-2024-12857
Updated: 2025-02-12T19:14:07.312Z
Status : Analyzed
Published: 2025-01-22T07:15:16.237
Modified: 2025-01-24T19:18:01.417
Link: CVE-2024-12857
No data.
OpenCVE Enrichment
No data.
EUVD