Skip to main content

CVE-2024-9305

8.1
HIGHCVSS v3.1 Base Score
0.49%
LOW RiskEPSS (66th percentile)

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() functions not having enough controls to prevent a successful brute force attack of the OTP to change a password, or verify that a password reset request came from an authorized user. This makes it possible for unauthenticated attackers to generate and brute force an OTP that makes it possible to change any users passwords, including an administrator.

Published: 10/16/2024
Modified: 5/17/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

0.49%LOW Exploitation Risk
66th percentile

This vulnerability has a 0.49% probability of being exploited in the next 30 days, ranking higher than 66% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-640)

CVE-2025-4319CRITICAL 9.4

Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute Force, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

1/23/2026
CVE-2024-8878CRITICAL 9.8

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.

9/25/2024
CVE-2024-8692MEDIUM 5.3

A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

9/11/2024
CVE-2024-38468CRITICAL 9.8

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.

6/16/2024
CVE-2023-7264HIGH 8.1

The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.

6/11/2024

Similar SeverityHIGH