CVE-2025-1570
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 28, 2025
Updated: Mar 6, 2025
CWE ID 640
Summary
CVE-2025-1570 is a privilege escalation vulnerability affecting the Directorist plugin for WordPress, versions up to 8.1. The issue lies in the inadequate security measures of the directorist_generate_password_reset_pin_code() and reset_user_password() functions. These functions fail to prevent successful brute force attacks on One-Time Passwords (OTPs), allowing unauthenticated attackers to alter any user's passwords, including administrator accounts. This poses a significant risk for account takeover and potential data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.