Access violation vulnerability in YITH Easy Login & Register Popup for WooCommerce 1.8.0

The YITH Easy Login & Register Popup for WooCommerce plugin for WordPress has a security issue that allows unauthorized people to reset the passwords of administrators. This problem affects versions up to 1.8.0 and happens because the plugin does not properly check if someone is allowed to reset a password for a given user. This makes it possible for people who are not logged in to reset administrators’ passwords and then log in to the site with that account.

Detected in:

YITH Easy Login & Register Popup for WooCommerce fixed vulnerable versions: >= * <= 1.8.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.