CyberRota Analysis
AI-GeneratedThe Login & Register Forms WordPress plugin prior to version 3.2.5 is vulnerable due to inadequate enforcement of rate limits on its password-reset verification-code process, allowing unauthenticated attackers to manipulate the attempt counter. This flaw enables attackers to brute-force the verification code, potentially leading to account takeovers, including administrative accounts, when the reset mode is active. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.
Original NVD Description
The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.