Access violation vulnerability in Ace User Management 2.0.3

A popular plugin for WordPress called Ace User Management has a security flaw that can lead to unauthorized access to user accounts. This flaw affects all versions of the plugin, including the latest one. The problem is that the plugin does not properly check a user’s identity before allowing them to change their password. This means that anyone, even without an account, can change the password of any user, including administrators, and use that to log into their account.

Detected in:

Ace User Management fixed vulnerable versions: >= * <= 2.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.