CVE Database
/

CVE-2023-0940

Back to search

CVE-2023-0940

Published: Mar 20, 2023

Modified: Feb 26, 2025

PUBLISHED

Description

The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones.

VendorProductVersions

Unknown

ProfileGrid

affected
0 - < 5.3.1

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now