CVE-2025-31524: WordPress WP User Profiles plugin <= 2.6.2 - Privilege Escalation vulnerability
Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Escalation.This issue affects WP User Profiles: from n/a through <= 2.6.2.
Other sources
Incorrect Privilege Assignment vulnerability in NotFound WP User Profiles allows Privilege Escalation. This issue affects WP User Profiles: from n/a through 2.6.2.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31524?
CVE-2025-31524 is rated as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-31524?
To mitigate CVE-2025-31524, update the WP User Profiles plugin to version 2.6.3 or later.
What software is affected by CVE-2025-31524?
CVE-2025-31524 affects WP User Profiles versions from n/a up to and including 2.6.2.
What type of vulnerability is CVE-2025-31524?
CVE-2025-31524 is an Incorrect Privilege Assignment vulnerability.
Can CVE-2025-31524 be exploited remotely?
Yes, CVE-2025-31524 can potentially be exploited remotely to escalate privileges.