PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Authentication Bypass to Account Takeover

2025-05-06 13:28
kr0d

Strategic Overview

Status
Patched in 8.0.0
Affected Version1.9.1 – 7.5.2
CVSS9.8Critical
CVECVE-2025-3844
View all PeproDev Ultimate Profile Solutions vulnerabilities

Vulnerability Overview

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to 7.5.2. This is due to handel_ajax_req() function not having proper restrictions on the change_user_meta functionality that makes it possible to set a OTP code and subsequently log in with that OTP code. This makes it possible for unauthenticated attackers to login as other users on the site, including administrators.

Technical Analysis

REMEDIATION: Update to version 8.0.0, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C