The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.7. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Apr 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.7. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account. | |
Title | Frontend Login and Registration Blocks <= 1.0.7 - Authenticated (Subscriber+) Privilege Escalation via Password Reset | |
Weaknesses | CWE-620 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-04-24T08:23:49.815Z
Updated: 2025-04-24T13:55:34.115Z
Reserved: 2025-04-14T19:58:14.576Z
Link: CVE-2025-3607

Updated: 2025-04-24T13:55:14.385Z

Status : Awaiting Analysis
Published: 2025-04-24T09:15:31.730
Modified: 2025-04-29T13:52:47.470
Link: CVE-2025-3607

No data.