PT-2025-19912 · WordPress · Peprodev Ultimate Profile Solutions

Kenneth Dunn

·

Published

2025-05-07

·

Updated

2025-05-07

·

CVE-2025-3924

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PeproDev Ultimate Profile Solutions plugin for WordPress (affected versions not specified)
Description The issue allows unauthorized access to data via a publicly exposed reset-password endpoint. The plugin looks up the valid email value based solely on a supplied username parameter, without verifying that the requester is associated with that user account. This enables unauthenticated attackers to enumerate email addresses for any user, including administrators.
Recommendations For the PeproDev Ultimate Profile Solutions plugin, consider disabling the reset-password endpoint until a patch is available. Restrict access to the endpoint to minimize the risk of exploitation. Avoid using the username parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-3924

Affected Products

Peprodev Ultimate Profile Solutions