The flaw affects all versions of the plugin up to 6.3.0.1 and allows attackers to escalate privileges without authentication, giving them the ability to create rogue administrator accounts. The vulnerability arises from a weak hash check in the plugin’s user simulation feature, which can be brute-forced to gain unauthorized access.
Source: SC Magazine