ZeroHour

CVE-2025-47646

Weak Password Recovery in PSW Front-end Login & Registration WordPress Plugin

CVSS 3.1
9.8 critical
EPSS
25%p98
Published
()
Modified
AI analysis

The WordPress plugin PSW Front-end Login & Registration by Gilblas Ngunte Possi contains a weak password recovery mechanism (CWE-640) in its forgotten-password flow, affecting all versions through 1.13. The flaw is reachable over the network with no authentication, privileges, or user interaction required, allowing an attacker to abuse the password-recovery process. Successful exploitation enables the attacker to recover or reset another account's password, including administrator accounts, leading to full account takeover with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8). Any WordPress site running the plugin at version 1.13 or earlier is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the EPSS score of 24.9% (98th percentile) indicates a meaningful probability of exploitation within the next 30 days.

What to do: Update PSW Front-end Login & Registration to a patched release newer than version 1.13 as soon as one is available. If no fix has shipped yet, deactivate the plugin until an update is released, and check sites for unexpected password-reset emails, unauthorized password changes, or modified administrator accounts. Monitor logs for unauthenticated requests targeting the password-recovery flow.

Affected
Gilblas Ngunte Possi PSW Front-end Login & Registration (psw-login-and-registration)all versions from n/a through <= 1.13
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13.

Ecosystems
WordPress
Weakness
CWE-640
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.