Aller au contenu

Fiche vulnérabilité

CVE-2023-4214 : faille critique apppresser apppresser (CVSS 9.8)

Description

The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
18 nov. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • apppresser apppresser

Références

Rechercher une autre vulnérabilité dans la base CVE