ZeroHour

CVE-2025-6027

CVSS 3.1
6.3 medium
EPSS
<1%p7
Published
()
Modified
Description

The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, allowing any authenticated users, such as subscriber to reset the password of arbitrary accounts, including administrators.

Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.