CVE-2025-47646
—Weak Password Recovery in PSW Front-end Login & Registration WordPress Plugin
The WordPress plugin PSW Front-end Login & Registration by Gilblas Ngunte Possi contains a weak password recovery mechanism (CWE-640) in its forgotten-password flow, affecting all versions through 1.13. The flaw is reachable over the network with no authentication, privileges, or user interaction required, allowing an attacker to abuse the password-recovery process. Successful exploitation enables the attacker to recover or reset another account's password, including administrator accounts, leading to full account takeover with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8). Any WordPress site running the plugin at version 1.13 or earlier is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the EPSS score of 24.9% (98th percentile) indicates a meaningful probability of exploitation within the next 30 days.
What to do: Update PSW Front-end Login & Registration to a patched release newer than version 1.13 as soon as one is available. If no fix has shipped yet, deactivate the plugin until an update is released, and check sites for unexpected password-reset emails, unauthorized password changes, or modified administrator accounts. Monitor logs for unauthenticated requests targeting the password-recovery flow.
| Gilblas Ngunte Possi PSW Front-end Login & Registration (psw-login-and-registration) | all versions from n/a through <= 1.13 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13.
- Ecosystems
- WordPress
- Weakness
- CWE-640
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.