Authentication vulnerability in AdForest 5.1.6

The AdForest theme for WordPress has a security issue that could allow unauthorized users to gain access to accounts. This vulnerability affects all versions of the theme up to and including 5.1.6. The problem is that the plugin does not properly check a user’s identity before allowing them to change their password using the adforest_reset_password() function. This means that anyone, even without a valid account, could change the passwords of any user, including administrators, and potentially access their account.

Detected in:

AdForest fixed vulnerable versions: >= * <= 5.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.