What the vulnerability does
01Description
Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Important Client Functionality.This issue affects LoginPress Pro: from n/a before 3.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Important Client Functionality.This issue affects LoginPress Pro: from n/a before 3.0.0.
Explanation of Vulnerability in Simple Terms
LoginPress Pro versions before 3.0.0 contain a weakness in password reset token generation that allows attackers to predict or brute-force reset tokens without authentication. An attacker can use this to reset user passwords and gain unauthorized account access. Update to version 3.0.0 or later to fix the vulnerability.
What an attacker can do
Reset user passwords and take over accounts without knowing the current password.
Potential impact on your site
User accounts can be compromised if attackers reset passwords and log in as legitimate users.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities