Privilege Escalation Vulnerability in Frontend Login and Registration Blocks for WordPress
CVE-2025-3605
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 May 2025
What is CVE-2025-3605?
The Frontend Login and Registration Blocks plugin for WordPress is susceptible to privilege escalation due to insufficient validation of user identity when updating account details. Attackers without authentication can exploit this vulnerability to change any user's email address, including that of administrators. This manipulation allows them to reset passwords and take over accounts, posing significant risks to WordPress sites. This issue affects all versions up to and including 1.0.7, necessitating immediate action to secure vulnerable systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Frontend Login and Registration Blocks * <= 1.0.7
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved