CVE-2023-7264: Build App Online <= 1.0.22 - Account Takeover via Weak Password Reset Mechanism
Published Jun 11, 2024
·Updated
The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.
Affected Software
2 affected components
Build App Build App Online<=1.0.21
Buildapp Build App Online Wordpress<=1.0.21
Event History
Jun 11, 2024
CVE Published
via MITRE·03:16 AM
Data Sourced
via MITRE·03:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-7264?
CVE-2023-7264 has a medium severity rating due to its potential for account takeover.
2
How do I fix CVE-2023-7264?
To fix CVE-2023-7264, update the Build App Online plugin to version 1.0.22 or later.
3
Who is affected by CVE-2023-7264?
All users of the Build App Online plugin for WordPress versions up to and including 1.0.21 are affected by CVE-2023-7264.
4
What type of attack is possible with CVE-2023-7264?
CVE-2023-7264 allows unauthenticated attackers to reset passwords of arbitrary users, leading to account takeover.
5
When was CVE-2023-7264 disclosed?
CVE-2023-7264 was disclosed in October 2023.