🔐 CVE Alert

CVE-2023-4915

MEDIUM 5.3

WP User Control <= 1.5.3 - Insecure Password Reset Mechanism

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (in the WP User Control Widget). The function changes the user's password after providing the email. The new password is only sent to the user's email, so the attacker does not have access to the new password.

CWE CWE-620
Vendor wmsedgar
Product wp user control
Published Sep 13, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for wmsedgar wp user control

Be the first to know when new medium vulnerabilities affecting wmsedgar wp user control are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

wmsedgar / WP User Control
0 ≤ 1.5.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/f4ca1736-7b99-49db-9367-586dbc14df41?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-user-control/tags/1.5.3/inc/WPUserControlWidget.php#L893

Credits

István Márton