The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.
History

Thu, 24 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 08:45:00 +0000

Type Values Removed Values Added
Description The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.
Title Buddypress Force Password Change <= 0.1 - Authenticated (Subscriber+) Account Takeover via Password Update
Weaknesses CWE-620
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-04-24T08:23:52.234Z

Updated: 2025-04-24T13:06:26.570Z

Reserved: 2025-04-18T10:14:40.302Z

Link: CVE-2025-3793

cve-icon Vulnrichment

Updated: 2025-04-24T13:04:06.662Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-24T09:15:32.077

Modified: 2025-04-29T13:52:47.470

Link: CVE-2025-3793

cve-icon Redhat

No data.