CVE-2021-24527
Profile Builder < 3.4.9 - Admin Access via Password Reset
Record summary
CVE-2021-24527 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore, the admin will not be notified of such change by email for example.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 11, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
User Registration & User Profile – Profile Builder | CVE List | 3.4.9 to < 3.4.9 | affected |
profile_builderBrowse cozmoslabs / profile_builder | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALProfile Builder < 3.4.9 - Improper AuthenticationCVSS 9.8
The Profile Builder plugin before 3.4.9 for WordPress allows unauthenticated attackers to gain administrative access by exploiting an improper authentication vulnerability in the password reset functionality. An attacker can reset the password of any user, including administrators, without proper authorization, leading to a complete site compromise.
Impact
Unauthenticated attackers can reset passwords for any user including administrators without authorization, leading to complete site compromise and account takeover.
Remediation
Fixed in 3.4.9
Source: ProjectDiscovery