PT-2026-7806 · WordPress · Adforest
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AdForest versions up to and including 6.0.12
Description
The AdForest theme for WordPress is susceptible to authentication bypass. The issue stems from insufficient user identity verification before authentication via the
sb login user with otp fun function. This allows unauthenticated attackers to log in as any user, including administrators.Recommendations
Versions prior to and including 6.0.12 should be updated when a patch becomes available. As a temporary workaround, consider restricting access to the
sb login user with otp fun function until a patch is available.Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Adforest