CVE detail
CVE-2023-4915 — CVE-2023-4915
Published 2023-09-13 · Modified 2026-06-17 · Vendor palmspark · Product wp_user_control · Source nvd
MEDIUM
severity
CVSS-derived band
0.0038
EPSS probability
exploitation probability, 30d
30.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 1.5.3. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (in the WP User Control Widget). The function changes the user's password after providing the email. The new password is only sent to the user's email, so the attacker does not have access to the new password.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References