Description

The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.

INFO

Published Date :

2024-06-11T03:16:59.623Z

Last Modified :

2026-04-08T17:33:26.719Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2023-7264 vulnerability.

Vendors Products
Buildapp
  • Build App Online
Rahamsolutions
  • Build App Online

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact