CVE · High

CVE-2019-10270 — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.40

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-10270 Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.0.40 Weak Password Recovery Mechanism for Forgotten Password High 8.8 < 2.0.40 2.0.40 2019-06-15

CVE-2019-10270

The Ultimate Member plugin before version 2.0.40 contains an arbitrary password reset vulnerability that allows attackers to reset passwords for any user account. The flaw exists because the password reset functionality fails to properly validate the relationship between the reset token sent via email and the user ID parameter in the request, enabling an attacker who knows a target user's publicly visible ID to intercept and modify the password change request to reset arbitrary accounts. Successful exploitation could result in unauthorized access to any user account, including administrative accounts, leading to account takeover and potential privilege escalation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.