The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, allowing any authenticated users, such as subscriber to reset the password of arbitrary accounts, including administrators.
References
Configurations
No configuration.
History
05 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.3 |
05 Nov 2025, 06:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-05 06:15
Updated : 2025-11-06 19:45
NVD link : CVE-2025-6027
Mitre link : CVE-2025-6027
CVE.ORG link : CVE-2025-6027
JSON object : View
Products Affected
No product.
CWE
No CWE.
