The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Tue, 06 Jan 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account. | |
| Title | FS Registration Password <= 1.0.1 - Unauthenticated Privilege Escalation via Account Takeover | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-01-06T04:31:55.460Z
Updated: 2026-01-06T14:37:02.949Z
Reserved: 2025-12-20T18:36:03.748Z
Link: CVE-2025-15001
Updated: 2026-01-06T14:36:59.822Z
Status : Received
Published: 2026-01-06T05:16:04.443
Modified: 2026-01-06T05:16:04.443
Link: CVE-2025-15001
No data.