CVE-2021-24655

The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:wpusermanager:wp_user_manager:*:*:*:*:*:wordpress:*:*

Information

Published : 2022-07-17 04:15

Updated : 2022-07-18 06:34


NVD link : CVE-2021-24655

Mitre link : CVE-2021-24655


JSON object : View

CWE
CWE-639

Authorization Bypass Through User-Controlled Key

Advertisement

dedicated server usa

Products Affected

wpusermanager

  • wp_user_manager