Ace User Management

Ace User Management has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (100%).

The one issue recorded for Ace User Management has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by aschoiloa1890. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Ace User Management vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-6027

Ace User Management <= 2.0.3 - Unauthenticated Privilege Escalation via Password Reset

Read the full analysis

Vulnerability Records

1 records
Ace User Management banner
Latestv2.6

Ace User Management

Acewebx

Author

Acewebx

0.0(0)
0/100
Last Updated
2025-12-18 (9mo ago)
Active Installs
0+
Downloads
3,349
Requires WP
3.0.1+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2019-01-12 (8y ago)

This plugin helps us create a registration form with unlimited custom fields. It also provides Captcha to prevent spamming in the registration form. ⚡️ FEATURES Create fields in the registration form according to your needs for users. Set custom fields based on your requirements. Update custom fields and delete them in your template. Set reCAPTCHA on your login page and registration page. Customize the stylesheet only for plugin pages. This panel comes with 6 different languages (Hebrew, Spanish, Japanese, Chinese, Portuguese, German).

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C