Access violation vulnerability in Resideo Plugin for Resideo – Real Estate WordPress Theme 2.5.4

The Resideo Plugin for Resideo – Real Estate WordPress Theme is not secure and can be easily taken over by someone who is not authorized. This is because the plugin does not have proper security measures in place to verify a user’s identity before allowing them to change their email address. This means that anyone with access to the plugin can change the email address of any user, including administrators, and use that to reset their password and gain access to their account.

Detected in:

Resideo Plugin for Resideo - Real Estate WordPress Theme open vulnerable versions: >= * <= 2.5.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.