Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-3924

Опубликовано: 07 мая 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its publicly exposed reset-password endpoint. The plugin looks up the 'valid_email' value based solely on a supplied username parameter, without verifying that the requester is associated with that user account. This allows unauthenticated attackers to enumerate email addresses for any user, including administrators.

EPSS

Процентиль: 34%
0.00136
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 5.3
github
9 месяцев назад

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its publicly exposed reset-password endpoint. The plugin looks up the 'valid_email' value based solely on a supplied username parameter, without verifying that the requester is associated with that user account. This allows unauthenticated attackers to enumerate email addresses for any user, including administrators.

EPSS

Процентиль: 34%
0.00136
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285