PT-2026-1413 · WordPress · As Password Field In Default Registration Form

·

CVE-2025-14996

·

Published

2026-01-06

·

Updated

2026-01-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AS Password Field In Default Registration Form plugin for WordPress versions prior to 2.0.1
Description The plugin does not properly validate a user’s identity before allowing password updates. This allows unauthenticated attackers to change passwords for any user, including administrators, leading to account takeover. The issue involves a privilege escalation, enabling attackers to gain unauthorized access to accounts.
Recommendations Update to version 2.0.1 or later.

Fix

LPE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14996

Affected Products

As Password Field In Default Registration Form