Impact
The Login & Register Forms WordPress plugin fails to tie the password reset verification state to the specific account or the verifier; instead it depends on an address header supplied by the client. Because this value is controllable by an unauthenticated user, anyone who can craft such a header can complete the reset verification process and effectively assume control of any user account that has recently reset its password, including administrative accounts. This gives an attacker full read, write, and administrative privileges on the compromised account, allowing complete compromise of confidentiality, integrity, and availability of that account's data and capabilities.
Affected Systems
All installations of the Login & Register Forms plugin rated prior to version 4.0.2 are affected. The plugin is distributed by an unnamed vendor within the WordPress ecosystem.
Risk and Exploitability
The vulnerability can be exploited remotely without any user interaction beyond initiating a password reset. Because the attacker only needs to supply a crafted address header, the attack vector is straightforward for a remote adversary. No additional conditions such as elevated privileges or knowledge of a specific user are stated in the advisory. The CVSS score is 8.1, the EPSS score is < 1%, and it is not listed in CISA KEV; nevertheless, the flaw presents a high potential for exploitation and a consequential impact.
OpenCVE Enrichment