What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions.
Explanation of Vulnerability in Simple Terms
LH Password Changer versions 1.55 and earlier are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted password changes or other administrative actions without the admin's knowledge or consent. The vulnerability requires user interaction—the admin must visit the attacker's page while authenticated.
What an attacker can do
Trick an authenticated admin into performing unwanted password changes or administrative actions via a malicious webpage.
Potential impact on your site
An attacker can change passwords or modify settings for any admin who visits a malicious link while logged in, potentially locking out legitimate administrators.
Conditions required to exploit
Admin must be logged in and visit an attacker-controlled webpage; no special privileges or complex setup required.
Key dates
External resources
Related vulnerabilities