CVE-2019-10270: High severity ultimate member vulnerability
An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due to lack of verification and correlation between the reset password key sent by mail and the userid parameter) to reset the password of another user. One only needs to know the userid, which is publicly available. One just has to intercept the password modification request and modify userid. It is possible to modify the passwords for any users or admin WordPress Ultimate Members. This could lead to account compromise and privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-10270.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Ultimate Member plugin 2.39 for WordPress.
What is the severity of CVE-2019-10270?
The severity of CVE-2019-10270 is high with a severity value of 8.8.
How can the arbitrary password reset issue be exploited?
It is possible to reset the password of another user by exploiting the lack of verification and correlation between the reset password key sent by mail and the user_id parameter.
Is there a fix available for this vulnerability?
There is no information available about a fix for this vulnerability. It is recommended to update to a newer version if available or apply any patches or mitigations provided by the vendor.