脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
脆弱性説明
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. The plaintext key stored in `wp_usermeta` can be used with the plugin's custom reset action to set a new password for any user. Combined with another vulnerability such as SQL Injection (CVE-2026-9700), this makes it possible for unauthenticated attackers to extract the plaintext reset key and take over any user account, including administrators. Note: The password reset function only works up to PHP version 7.4.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
脆弱性タイプ
使用候选名称进行的认证绕过
脆弱性タイトル
WordPress Eventer 授权问题漏洞
脆弱性説明
WordPress Eventer是WordPress基金会的一款管理事件的组件。 WordPress Eventer 4.4.2及之前版本存在授权问题漏洞,该漏洞源于不安全的密码重置机制,插件在用户请求密码重置时将明文重置密钥存储在eventer_verification_code用户元字段中,该密钥可用于插件自定义重置操作为任意用户设置新密码,攻击者可提取明文重置密钥并接管任意用户账户包括管理员账户。
CVSS情報
N/A
脆弱性タイプ
N/A