Buddypress Force Password Change <= 0.1 - Authenticated (Subscriber+) Account Takeover via Password Update
mediumThe Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authe...
- CVSS:
- 4.2
- Affected:
- up to 0.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 23, 2025