漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
Vulnerability Description
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. The plaintext key stored in `wp_usermeta` can be used with the plugin's custom reset action to set a new password for any user. Combined with another vulnerability such as SQL Injection (CVE-2026-9700), this makes it possible for unauthenticated attackers to extract the plaintext reset key and take over any user account, including administrators. Note: The password reset function only works up to PHP version 7.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
使用候选名称进行的认证绕过
Vulnerability Title
WordPress Eventer 授权问题漏洞
Vulnerability Description
WordPress Eventer是WordPress基金会的一款管理事件的组件。 WordPress Eventer 4.4.2及之前版本存在授权问题漏洞,该漏洞源于不安全的密码重置机制,插件在用户请求密码重置时将明文重置密钥存储在eventer_verification_code用户元字段中,该密钥可用于插件自定义重置操作为任意用户设置新密码,攻击者可提取明文重置密钥并接管任意用户账户包括管理员账户。
CVSS Information
N/A
Vulnerability Type
N/A