Authentication vulnerability in IMITHEMES Listing 3.3

The IMITHEMES Listing plugin has a security issue that allows unauthorized users to gain higher privileges by taking over another user’s account. This can happen in all versions of the plugin, up to version 3.3. The problem is caused by the plugin not checking a verification code before allowing a user to reset their password through the imic_reset_password_init() function. This means that anyone who is not logged in can change the password of any user, including administrators, if they know the user’s email address.

Detected in:

IMITHEMES Listing fixed vulnerable versions: >= * <= 3.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.