Privilege Escalation Vulnerability in Frontend Login and Registration Blocks for WordPress
CVE-2025-3605

9.8CRITICAL

What is CVE-2025-3605?

The Frontend Login and Registration Blocks plugin for WordPress is susceptible to privilege escalation due to insufficient validation of user identity when updating account details. Attackers without authentication can exploit this vulnerability to change any user's email address, including that of administrators. This manipulation allows them to reset passwords and take over accounts, posing significant risks to WordPress sites. This issue affects all versions up to and including 1.0.7, necessitating immediate action to secure vulnerable systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Frontend Login and Registration Blocks * <= 1.0.7

References

EPSS Score

14% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.