The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apppresser
Apppresser apppresser |
|
CPEs | cpe:2.3:a:apppresser:apppresser:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Apppresser
Apppresser apppresser |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator. | |
Title | AppPresser – Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP | |
Weaknesses | CWE-640 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T02:05:04.962Z
Updated: 2024-10-16T13:35:08.179Z
Reserved: 2024-09-27T17:38:50.213Z
Link: CVE-2024-9305
Vulnrichment
Updated: 2024-10-16T13:35:01.471Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T02:15:07.050
Modified: 2024-10-16T16:38:14.557
Link: CVE-2024-9305
Redhat
No data.