PT-2025-23374 · WordPress · Psw Front-End Login & Registration

Kenneth Dunn

·

Published

2025-05-31

·

Updated

2025-06-05

·

CVE-2025-4607

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PSW Front-end Login & Registration plugin for WordPress versions up to, and including, 1.12
Description The issue is related to Privilege Escalation due to a weak, low-entropy OTP mechanism used in the forget() function. This allows unauthenticated attackers to initiate a password reset for any user, including administrators, potentially leading to full site takeover. The customer registration() function is also implicated in this issue.
Recommendations For versions up to, and including, 1.12, consider disabling the customer registration() function and restricting the use of the forget() function until a patch is available. Additionally, avoid using the weak OTP mechanism in the forget() function to minimize the risk of exploitation.

Fix

LPE

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2025-4607

Affected Products

Psw Front-End Login & Registration