CVE detail
CVE-2021-24655 — CVE-2021-24655
Published 2022-07-17 · Modified 2026-06-17 · Vendor wpusermanager · Product wp_user_manager · Source nvd
HIGH
severity
CVSS-derived band
0.0102
EPSS probability
exploitation probability, 30d
60.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References