Authentication vulnerability in WP User Control 1.5.3

The WP User Control plugin for WordPress is vulnerable to unauthorized password resets in versions up to and including 1.5.3. This means that if someone knows the email address associated with your account, they can change your password without requiring your permission. The plugin uses native password reset functionality, which should have been more secure, but it does not properly check the password reset function (the WP User Control Widget). When a user’s email is provided, the new password is automatically sent to the user’s email address without the attacker having access to the new password.

Detected in:

WP User Control open vulnerable versions: >= * <= 1.5.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.