PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Unauthenticated Email Enumeration

2025-05-06 13:27
kr0d

Strategic Overview

Status
Patched in 8.0.0
Affected Version1.9.1 – 7.5.2
CVSS5.3Medium
CVECVE-2025-3924
View all PeproDev Ultimate Profile Solutions vulnerabilities

Vulnerability Overview

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its publicly exposed reset-password endpoint. The plugin looks up the 'valid_email' value based solely on a supplied username parameter, without verifying that the requester is associated with that user account. This allows unauthenticated attackers to enumerate email addresses for any user, including administrators.

Technical Analysis

REMEDIATION: Update to version 8.0.0, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C