Vulnerability found in Ultimate AI

The UltimateAI plugin for WordPress has a security issue where hackers can bypass the login process and reset the password of the first user. This vulnerability affects all versions of the plugin up to version 2.8.3. It is caused by a flaw in the code that does not properly check for empty values and does not have a default activated value. This means that attackers who are not logged in can gain access to the account of the first user who has not activated their account or the first user who has activated their account but is only a subscriber.

Detected in:

Ultimate AI open vulnerable versions: >= * <= 2.8.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.