Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability in a WordPress plugin allows unauthenticated attackers to bypass authorization. If a specific feature is enabled, attackers could exploit this to exfiltrate password reset URLs and take over user accounts, including those of administrators.
- Unauthenticated access to reset links.
- Account takeover risk for any user.
- Confirm if the feature is enabled.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can compromise user accounts by exploiting an authorization bypass in the WPMobile.App WordPress plugin. This is possible when the plugin's mail-to-push feature is enabled, which causes password-reset URLs to be exposed in a push queue. An attacker can then access these URLs and use them to take over targeted accounts.
- No prior authentication needed.
- Exploits mail-to-push feature for URLs.
- Allows account takeover.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to obtain password-reset URLs for any user, including administrators, when the mail-to-push feature is enabled. These URLs could then be used to take over targeted accounts.
- User and administrator account credentials.
- Through an authorization bypass flaw.
- Account takeover and unauthorized access.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WordPress plugin's authorization bypass vulnerability requires administrators to identify instances where the "mail-to-push" feature is enabled to prevent unauthenticated attackers from exfiltrating password-reset URLs. Website owners, application administrators, and potentially infrastructure teams should collaborate to locate affected sites, confirm the enabled feature, and plan for remediation, prioritizing critical or publicly exposed systems.
- WordPress site owners and admins.
- Verify "mail-to-push" feature is enabled.
- Plan remediation for enabled features.