CVE 6.3 MEDIUM

Ace User Management <= 2.0.3 - Subscriber+ Authentication Bypass via Password Rest_CVE-2025-6027

6.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Description

The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, allowing any authenticated users, such as subscriber to reset the password of arbitrary accounts, including administrators.

Basic Information

ID CVE-2025-6027
Source WPScan
Published Nov 5, 2025 at 06:00
Modified Nov 5, 2025 at 18:35

Affected Product

Vendor Unknown
Product Ace User Management
Affected Versions Unknown Ace User Management 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.