CVE-2025-31380: WordPress Paid Videochat Turnkey Site plugin <= 7.3.11 - Broken Authentication Vulnerability
Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site allows Password Recovery Exploitation. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.11.
Other sources
Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Password Recovery Exploitation.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.11.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31380?
The severity of CVE-2025-31380 is moderate, as it involves a weak password recovery mechanism that can be exploited.
How do I fix CVE-2025-31380?
To fix CVE-2025-31380, update the Videowhisper Paid Videochat Turnkey Site to version 7.3.12 or later.
What versions of Paid Videochat Turnkey Site are affected by CVE-2025-31380?
CVE-2025-31380 affects versions of Paid Videochat Turnkey Site up to and including 7.3.11.
What types of vulnerabilities are associated with CVE-2025-31380?
CVE-2025-31380 is associated with exploitations of password recovery mechanisms, specifically weak authentication vulnerabilities.
Is CVE-2025-31380 applicable to WordPress?
Yes, CVE-2025-31380 is applicable to the WordPress Paid Videochat Turnkey Site plugin.