ZeroHour

CVE-2021-24655

PoC
CVSS 3.1
7.5 high
EPSS
1%p62
Published
()
Modified
Description

The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.

Vendors
wpusermanager
Products
wp user manager
Ecosystems
WordPress
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.