CVE-2019-10270
The Ultimate Member plugin before version 2.0.40 contains an arbitrary password reset vulnerability that allows attackers to reset passwords for any user account. The flaw exists because the password reset functionality fails to properly validate the relationship between the reset token sent via email and the user ID parameter in the request, enabling an attacker who knows a target user's publicly visible ID to intercept and modify the password change request to reset arbitrary accounts. Successful exploitation could result in unauthorized access to any user account, including administrative accounts, leading to account takeover and potential privilege escalation.
Based on public CVE data (MITRE/NVD).