9.8
CVE-2024-11350
- EPSS 0.43%
- Veröffentlicht 08.01.2025 09:15:06
- Zuletzt bearbeitet 12.08.2025 16:07:54
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
AdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account Takeover
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adforest_reset_password() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Mögliche Gegenmaßnahme
AdForest: Update to version 5.1.7, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Theme
≫
Produkt
AdForest
Version
*-5.1.6
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Scriptsbundle ≫ Adforest SwPlatformwordpress Version < 5.1.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.62 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.