Junglewise Threat Intelligence

CVE-2024-35648: Andy Moyle Emergency Password Reset CSRF

CVE-2024-35648 · Severity: medium · CVSS 4.3 · Published 2026-06-17

Executive brief

The Emergency Password Reset plugin for WordPress is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By persuading a logged-in user to click a malicious link or visit a specially crafted webpage, an attacker could potentially trigger the plugin's functions without the user's consent. This could lead to unauthorized configuration changes or service disruptions depending on the plugin's specific capabilities.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Andy Moyle Emergency Password Reset plugin for WordPress (versions <= 8.0). The vulnerability stems from a lack of proper nonce validation or equivalent protection on sensitive plugin actions. An unauthenticated remote attacker can exploit this by tricking a site administrator into visiting a malicious URL or submitting a crafted form while authenticated. Successful exploitation allows the attacker to execute unauthorized actions on behalf of the administrator, potentially resetting passwords or modifying plugin settings. The issue is resolved in version 9.0.

Affected products

  • Andy Moyle Emergency Password Reset through 8.0

Timeline

  • 2024-05-12: other: Vulnerability reported by Pedro José Navas Pérez
  • 2024-06-03: advisory: Patchstack published advisory
  • 2024-06-17: disclosed: NVD publication date
  • 2024-06-03: patched: Version 9.0 released to address the issue

References