Threats Tagged 'cwe-640'
View all threats tagged with 'cwe-640'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-640'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-12417: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in pravel SignUp & SignInCVE-2026-12417 0 The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability check, and only a loose equality check between an attacker-supplied `reset_activation_code` POST parameter and the target user's `forgot_email` user meta value; when a user has never initiated a password reset, `get_user_meta()` returns an empty string that trivially satisfies this check against an omitted or empty attacker-supplied code. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by sending a crafted POST request to `admin-ajax.php` with `action=pravel_change_password`, `reset_user_id` set to the target account's user ID, and `new_password_custom` set to an attacker-chosen password. Successful exploitation allows the attacker to authenticate with the newly set password and fully take over the targeted account, achieving administrator-level privilege escalation on the affected site. Join the discussion | CVE Database V5 | 06/24/2026, 05:33:29 UTC Added: 06/24/2026, 06:24:17 UTC |
CVE-2026-12416: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in pravel Invoice GeneratorCVE-2026-12416 0 The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a loose equality comparison between the supplied `reset_activation_code` POST parameter and the target user's stored `forgot_email` user meta — a check that trivially evaluates to true (`'' == ''`) for any user who has never initiated a forgot-password request, which applies to administrators under normal conditions. This makes it possible for unauthenticated attackers to supply an arbitrary user ID via the `reset_user_id` POST parameter, bypass the activation code check entirely by omitting `reset_activation_code`, and set the target account's password to an attacker-chosen value, enabling full takeover of any account on the site, including administrator accounts. Join the discussion | CVE Database V5 | 06/24/2026, 05:33:30 UTC Added: 06/24/2026, 06:24:17 UTC |
CVE-2026-11551: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in wpmudev Branda – White Label & Branding, Free Login Page CustomizerCVE-2026-11551 0 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account. Join the discussion | CVE Database V5 | 06/19/2026, 23:29:21 UTC Added: 06/19/2026, 23:41:33 UTC |
CVE-2026-45013: CWE-20: Improper Input Validation in apostrophecms apostropheCVE-2026-45013 0 ApostropheCMS versions up to and including 4.29.0 have an improper input validation vulnerability in the password reset flow. The reset URL is constructed using the HTTP Host header without proper validation when apos.baseUrl is not configured. This allows an unauthenticated attacker to craft a reset link pointing to an attacker-controlled domain and send it to a victim. If the victim clicks the link, the attacker receives the valid reset token, enabling full account takeover. No patch is currently available for this vulnerability. Join the discussion | CVE Database V5 | 06/12/2026, 20:46:21 UTC Added: 06/12/2026, 21:09:29 UTC |
CVE-2024-12604: CWE-526 Cleartext Storage of Sensitive Information in an Environment Variable in Tapandsign Technologies Tap&Sign AppCVE-2024-12604 0 Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse. This issue affects Tap&Sign App: before V.1.025. Join the discussion | CVE Database V5 | 03/10/2025, 14:28:12 UTC Added: 06/01/2026, 15:03:54 UTC |
CVE-2026-7459: CWE-640 Weak Password Recovery Mechanism for Forgotten Password in eskapism Simple History – Track, Log, and Audit WordPress ChangesCVE-2026-7459 0 The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_permissions_check() as their permission_callback, which only verifies the requester is logged in and does not enforce the per-logger capability checks normally applied by Log_Query. As a result, a Subscriber-level user can POST to /wp-json/simple-history/v1/events/<id>/react with the _fields=context query parameter and read the full context of any Simple History event — including SimpleUserLogger entries that record the full password-reset email body (reset URL with the reset key) for any user. The attacker triggers a password reset for an administrator via the lost-password form, brute-forces recent event IDs through the reaction endpoint to read the resulting user_requested_password_reset_link event, extracts the reset key from context.message, and completes the password reset to take over the administrator account. Exploitation requires an administrator to have first enabled the experimental features option (simple_history_experimental_features_enabled), which is not the default. Join the discussion | CVE Database V5 | 05/30/2026, 09:29:00 UTC Added: 05/30/2026, 09:49:34 UTC |
Showing 1 to 6 of 6 results