Description
The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3. This is due to the plugin not properly validating a verification code value prior to updating their password through the imic_reset_password_init() function. This makes it possible for unauthenticated attackers to change any user's passwords, including administrators if the users email is known.
Problem types
CWE-620 Unverified Password Change
Product status
* (semver)
Timeline
2025-05-08: | Disclosed |
Credits
Alyudin Nafiie
References
www.wordfence.com/...-9cbf-4033-a31f-6cb954e8ce01?source=cve
themeforest.net/...car-dealership-listings-wp-theme/11560490