Ace User Management
Ace User Management has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Authorization Bypass Through User-Controlled Key, behind 1 of the records (100%).
The one issue recorded for Ace User Management has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by aschoiloa1890. The current release is tested up to WordPress 6.9.7.
CVE-2025-6027Ace User Management <= 2.0.3 - Unauthenticated Privilege Escalation via Password Reset
Read the full analysisVulnerability Records

Ace User Management
Author
Acewebx
This plugin helps us create a registration form with unlimited custom fields. It also provides Captcha to prevent spamming in the registration form. ⚡️ FEATURES Create fields in the registration form according to your needs for users. Set custom fields based on your requirements. Update custom fields and delete them in your template. Set reCAPTCHA on your login page and registration page. Customize the stylesheet only for plugin pages. This panel comes with 6 different languages (Hebrew, Spanish, Japanese, Chinese, Portuguese, German).
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C