Impact
The Admin Safety Guard plugin for WordPress contains an authentication bypass that allows an attacker to exploit the password‑recovery mechanism via an alternate path or channel. The flaw permits changing a user’s password without verifying the current password, granting unauthorized access. This issue affects versions from the initial release through 1.2.6. The vulnerability is classified as CWE‑288, directly undermining the integrity of user credentials.
Affected Systems
Affected installations include any version of the Admin Safety Guard plugin from Themepaste dated through 1.2.6. Non‑upgraded installations remain susceptible to the vulnerability.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is below 1 % and it does not appear in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. The likely attack path involves requesting a password‑reset link, capturing or obtaining the reset token, and then using it to set a new password. This path is inferred from the description; the exact method of token acquisition is not detailed in the source. If an attacker can intercept or guess the reset link, account takeover is possible.
OpenCVE Enrichment