AdForest <= 5.1.6 - Authentication Bypass
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 9.8epss 1.2%
from disclosure to weapon
Published on NVDDec 21
VulnCheck+500d
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
yesVulnCheck
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
scriptsbundle · AdForest