plugin

Ace User Management Vulnerabilities

1 known security issue reported for the Ace User Management WordPress plugin. Most recent disclosed Oct 15, 2025.

1 critical

Running Ace User Management on your site? Check whether your installed version is affected.

Scan your site free

Ace User Management <= 2.0.3 - Unauthenticated Privilege Escalation via Password Reset

critical

The Ace User Management plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.3. This is due to the plugin not properly validating a user's identity prior to updating their details like their password. This makes it possible for unauthenticated attacke...

CVSS:
9.8
Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Oct 15, 2025

CVE-2025-6027 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database