Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset
Vulnerability Description
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress cafe-api 权限许可和访问控制问题漏洞
Vulnerability Description
WordPress cafe-api是WordPress基金会的一个为WordPress提供多端REST API接口封装的插件。 WordPress cafe-api 1.0.0及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于更新用户密码时缺乏身份验证或授权,可能导致未认证攻击者设置任意用户密码并完全接管账户。
CVSS Information
N/A
Vulnerability Type
N/A