Vulnerability Description
The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-15030?
CVE-2025-15030 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their usern...
How severe is CVE-2025-15030?
CVE-2025-15030 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-15030?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.