Unauthorized Data Modification in PeproDev Ultimate Profile Solutions Plugin for WordPress
CVE-2025-3921
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 May 2025
What is CVE-2025-3921?
The PeproDev Ultimate Profile Solutions plugin for WordPress contains a security vulnerability that allows unauthenticated users to modify arbitrary user metadata. This issue arises from the lack of necessary capability checks in the handel_ajax_req() function, particularly affecting versions 1.9.1 to 7.5.2. Exploitation of this flaw can lead to various malicious outcomes, such as hindering administrator access by manipulating user roles. Website administrators are advised to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PeproDev Ultimate Profile Solutions 1.9.1 <= 7.5.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved