PT-2025-23374 · WordPress · Psw Front-End Login & Registration

·

CVE-2025-4607

·

Publicado

2025-05-31

·

Atualizado

2025-06-05

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PSW Front-end Login & Registration plugin for WordPress versions up to, and including, 1.12
Description The issue is related to Privilege Escalation due to a weak, low-entropy OTP mechanism used in the forget() function. This allows unauthenticated attackers to initiate a password reset for any user, including administrators, potentially leading to full site takeover. The customer registration() function is also implicated in this issue.
Recommendations For versions up to, and including, 1.12, consider disabling the customer registration() function and restricting the use of the forget() function until a patch is available. Additionally, avoid using the weak OTP mechanism in the forget() function to minimize the risk of exploitation.

Correção

LPE

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-4607

Produtos afetados

Psw Front-End Login & Registration