The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, allowing any authenticated users, such as subscriber to reset the password of arbitrary accounts, including administrators.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, allowing any authenticated users, such as subscriber to reset the password of arbitrary accounts, including administrators.
Title Ace User Management <= 2.0.3 - Subscriber+ Authentication Bypass via Password Rest
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-11-05T06:00:07.919Z

Reserved: 2025-06-12T12:45:31.146Z

Link: CVE-2025-6027

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-05T06:15:34.373

Modified: 2025-11-05T06:15:34.373

Link: CVE-2025-6027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.