PT-2025-42292 · WordPress · Wpbifröst

Published

2025-10-15

·

Updated

2025-10-15

·

CVE-2025-10299

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPBifröst versions through 1.0.7
Description The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress has an issue that allows authenticated attackers with Subscriber-level access or higher to create new administrative user accounts. This is due to a missing capability check on the ctl create link AJAX action. Attackers can then log in as these newly created administrative users.
Recommendations Update to version 1.0.8.

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10299

Affected Products

Wpbifröst