Executive brief
The AllCoach plugin for WordPress, which is used for managing coaching and training services, contains a critical security flaw in its account registration process. An attacker can exploit this by registering a new account using the email address of an existing user, such as a site administrator. This action incorrectly overwrites the existing user's password, allowing the attacker to take full control of the website and its data.
Technical details
The AllCoach WordPress plugin before version 1.0.2 suffers from an unauthenticated account takeover vulnerability. The root cause is a lack of validation in the public account-registration endpoint, which fails to check if a submitted email address is already associated with an existing user account. When a duplicate email is submitted, the plugin overwrites the password of the existing user record with the new password provided during registration. An unauthenticated remote attacker can exploit this to reset the password of any user, including administrators, by knowing their email address. This vulnerability is fixed in version 1.0.2.
Affected products
- Unknown AllCoach < 1.0.2
Timeline
- 2026-06-15: disclosed: Publicly published by WPScan
- 2026-07-06: advisory: NVD publication date
- 2026-07-06: patched: Fixed in version 1.0.2