PT-2025-48376 · WordPress · Streamtube Core
Friderika Baranyai
·
Published
2025-11-30
·
Updated
2025-12-05
·
CVE-2025-13615
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
StreamTube Core plugin for WordPress versions up to and including 4.78
Description
The StreamTube Core plugin for WordPress is susceptible to Arbitrary User Password Change. This occurs because the plugin grants user-controlled access to objects, allowing bypass of authorization and access to system resources. This enables unauthenticated attackers to modify user passwords, potentially gaining control of administrator accounts. This exploitation is possible if the 'registration password fields' are enabled in the theme options.
Recommendations
Versions prior to 4.78: Disable the 'registration password fields' in theme options as a temporary measure.
Versions prior to 4.78: Update to a newer version that addresses this issue as soon as it becomes available.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Streamtube Core