CVE-2025-14996

9.8

Akshar Soft Solutions · AS Password Field In Default Registration Form

The AS Password Field In Default Registration Form plugin for WordPress allows unauthenticated attackers to perform account takeovers by resetting arbitrary user passwords.

Executive summary

A critical privilege escalation vulnerability in the AS Password Field In Default Registration Form plugin allows unauthenticated attackers to hijack administrative accounts and achieve full system compromise.

Vulnerability

The plugin fails to perform necessary identity validation when processing password updates, which allows an unauthenticated attacker to manipulate the password reset mechanism. This authorization bypass effectively grants the attacker full control over any user account, including those with administrative privileges.

Business impact

This vulnerability carries a CVSS score of 9.8, indicating a critical severity level due to the ease of exploitation and the potential for total system compromise. Successful exploitation grants attackers full administrative access, which can result in complete data exfiltration, unauthorized modification of site content, and potential distribution of malware to site visitors.

Remediation

Immediate Action: Since no specific patch version is currently identified, administrators should immediately deactivate and uninstall the plugin until a secure update is released by the vendor.

Proactive Monitoring: Review WordPress user account activity logs for suspicious password resets or unexpected administrative logins.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block unauthorized requests to password reset endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability cannot be overstated, as it provides a direct path for unauthenticated actors to seize control of WordPress administrative accounts. Organizations currently running the AS Password Field In Default Registration Form plugin must prioritize its immediate removal to prevent account takeover attacks. Please monitor the vendor's official WordPress plugin page for the release of a security patch before considering re-installation.

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Analyst report written

Sources

Originally found and disclosed by Drew Webber, per the CVE Program record.