CVE-2025-13615: StreamTube Core <= 4.78 - Unauthenticated Arbitrary User Password Change
The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts. Note: This can only be exploited if the 'registration password fields' enabled in theme options.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13615?
CVE-2025-13615 has a high severity rating due to its potential for allowing arbitrary user password changes.
How do I fix CVE-2025-13615?
To fix CVE-2025-13615, update the StreamTube Core plugin to version 4.79 or later.
What versions are affected by CVE-2025-13615?
CVE-2025-13615 affects versions of the StreamTube Core plugin up to and including 4.78.
What kind of attack does CVE-2025-13615 enable?
CVE-2025-13615 enables arbitrary user password changes that can bypass authorization.
Who is affected by CVE-2025-13615?
Any WordPress site using versions of the StreamTube Core plugin up to 4.78 is affected by CVE-2025-13615.