Back to search
CVE-2021-24655
Published: Jul 17, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.
| Vendor | Product | Versions |
|---|---|---|
Unknown | WP User Manager – User Profile Builder & Membership | affected 2.6.3 - < 2.6.3 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now