CVE-2025-3607
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-3607 is a privilege escalation vulnerability affecting the Frontend Login and Registration Blocks plugin for WordPress. The issue arises from the plugin's failure to adequately validate user identities during password updates. As a result, authenticated attackers with Subscriber-level access or higher can manipulate passwords for other users, including administrators, allowing unauthorized account access. This vulnerability poses a significant security risk and requires immediate patching for all WordPress sites utilizing the Frontend Login and Registration Blocks plugin, version 1.0.7 and below.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.