PT-2023-20108 · WordPress · Feather Login Page
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Feather Login Page plugin for WordPress versions 1.0.7 through 1.1.1
Description
The issue is related to Cross-Site Request Forgery due to missing nonce validation in the
createTempAccountLink function. This allows unauthenticated attackers to create a new user with administrator role by tricking a site administrator into performing a specific action, such as clicking on a link. An attacker can leverage this to obtain a login link or request a password reset to the new user's email address.Recommendations
For Feather Login Page plugin for WordPress versions 1.0.7 through 1.1.1, consider disabling the
createTempAccountLink function until a patch is available to prevent exploitation. Restrict access to administrator roles to minimize the risk of unauthorized account creation.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Feather Login Page