Impact
A weak password recovery mechanism allows an attacker to exploit the forgotten‑password functionality and reset user credentials without proper authorization. The flaw permits elevated access in the form of unauthorized authentication, potentially compromising the confidentiality, integrity, and availability of WordPress sites utilizing the plugin.
Affected Systems
The vulnerability affects the Videowhisper Paid Videochat Turnkey Site (ppv‑live‑webcams) plugin for WordPress. All releases up to and including version 7.3.11 are susceptible. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while the EPSS score of <1% suggests a low likelihood of exploitation at present. The vulnerability is not cataloged in CISA’s KEV list. Considering the plugin’s web‑based nature, the attack vector is inferred to be remote over HTTP/HTTPS, enabling an authenticated attacker to trigger the password reset flow without additional privileges.
OpenCVE Enrichment
EUVD