CVE-2025-3607

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 620

Summary

CVE-2025-3607 is a privilege escalation vulnerability affecting the Frontend Login and Registration Blocks plugin for WordPress. The issue arises from the plugin's failure to adequately validate user identities during password updates. As a result, authenticated attackers with Subscriber-level access or higher can manipulate passwords for other users, including administrators, allowing unauthorized account access. This vulnerability poses a significant security risk and requires immediate patching for all WordPress sites utilizing the Frontend Login and Registration Blocks plugin, version 1.0.7 and below.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share