Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability exists in a WordPress plugin that, under specific configuration conditions, could allow unauthenticated attackers to change user passwords and potentially gain control of administrator accounts. This issue affects the StreamTube Core plugin.
- Unauthenticated users could change passwords.
- Allows takeover of administrator accounts.
- Confirm relevance and potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker can change any user's password without needing to log in, by exploiting a flaw in how the StreamTube Core WordPress plugin handles user data. This is possible if the theme allows registration password fields to be enabled. By manipulating access to objects, an unauthenticated attacker can bypass security checks. If successful, this could lead to an attacker taking control of administrator accounts.
- Requires registration password fields enabled.
- Unauthenticated access to user object manipulation.
- Potential for full administrator account takeover.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated attackers could change user passwords and take over administrator accounts if the 'registration password fields' are enabled in theme options. This allows them to bypass authorization and access system resources.
- Administrator account access.
- Bypass authorization to change passwords.
- Potential account takeover.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects the StreamTube Core plugin for WordPress. Ownership likely resides with the application owner responsible for the WordPress site, in coordination with the platform or infrastructure team managing the web server environment. The first practical step is to identify all WordPress instances using this plugin, determine if the 'registration password fields' option is enabled, and confirm internet reachability to assess risk.
- Application owners manage the issue.
- Verify 'registration password fields' status.
- Plan remediation based on identified risk.