🔐 CVE Alert

CVE-2023-4213

HIGH 8.8

Simplr Registration Form Plus+ <= 2.4.5 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.4.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber-level permissions or above to change user passwords and potentially take over administrator accounts.

CWE CWE-639
Vendor mpvanwinkle77
Product simplr registration form plus+
Published Sep 13, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for mpvanwinkle77 simplr registration form plus+

Be the first to know when new high vulnerabilities affecting mpvanwinkle77 simplr registration form plus+ are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

mpvanwinkle77 / Simplr Registration Form Plus+
0 ≤ 2.4.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/6ddf0452-3afe-4ada-bccc-30c818968a81?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/simplr-registration-form/trunk/lib/profile.php#L148

Credits

István Márton