← back
CVE-2023-4214highCWE-620

AppPresser <= 4.2.5 - Insecure Password Reset Mechanism

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
The AppPresser plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 4.2.5. This is due to the plugin generating too weak a reset code, and the code used to reset the password has no attempt or time limit.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H