CyberRota Analysis
AI-GeneratedThe AllCoach WordPress plugin prior to version 1.0.2 is vulnerable as it fails to verify whether an email address submitted for account registration is already linked to an existing user, enabling unauthenticated attackers to reset passwords for any account, including those of administrators. This flaw poses a significant risk of unauthorized access and potential site takeover. WordPress site administrators and users of the AllCoach plugin should prioritize updating to the latest version to mitigate this high-severity vulnerability.
Original NVD Description
The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registration endpoint is not already associated with an existing user before overwriting that user's password, allowing unauthenticated attackers to reset the password of arbitrary accounts, including administrators, and take over the site.