Unauthorized Data Modification in PeproDev Ultimate Profile Solutions Plugin for WordPress
CVE-2025-3921

8.2HIGH

What is CVE-2025-3921?

The PeproDev Ultimate Profile Solutions plugin for WordPress contains a security vulnerability that allows unauthenticated users to modify arbitrary user metadata. This issue arises from the lack of necessary capability checks in the handel_ajax_req() function, particularly affecting versions 1.9.1 to 7.5.2. Exploitation of this flaw can lead to various malicious outcomes, such as hindering administrator access by manipulating user roles. Website administrators are advised to update to the latest version to mitigate this risk.

Affected Version(s)

PeproDev Ultimate Profile Solutions 1.9.1 <= 7.5.2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.