Description
The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.
Problem types
CWE-620 Unverified Password Change
Product status
Any version
Timeline
| 2025-04-11: | Discovered |
| 2025-04-23: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-77b1-4778-a5d0-b532df777d06?source=cve
plugins.trac.wordpress.org/...k/bp-force-password-change.php