Showing 1 vulnerability on this page for SignUp & SignIn

Signals CISA KEV Ransomware Nuclei
pravel vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability check, and only a loose equality check between an attacker-supplied `reset_activation_code` POST par

CWE-640Jun 24, 2026
CVSS9.8v3.1EPSS0.454%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX