Access violation vulnerability in PeproDev Ultimate Profile Solutions 7.5.2

The PeproDev Ultimate Profile Solutions plugin for WordPress has a security issue that allows people to access sensitive data without permission through a reset-password feature. This is because the plugin only checks the username, without checking if the person trying to access the data is actually the user associated with that account. This means that anyone, even without an account, can find out the email addresses of users, including administrators.

Detected in:

PeproDev Ultimate Profile Solutions fixed vulnerable versions: >= 1.9.1 <= 7.5.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.