CVE-2025-3924: PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Unauthenticated Email Enumeration
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its publicly exposed reset-password endpoint. The plugin looks up the 'validemail' value based solely on a supplied username parameter, without verifying that the requester is associated with that user account. This allows unauthenticated attackers to enumerate email addresses for any user, including administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3924?
CVE-2025-3924 is classified as a high-severity vulnerability due to its potential for unauthorized data access.
How do I fix CVE-2025-3924?
To fix CVE-2025-3924, update the PeproDev Ultimate Profile Solutions plugin to version 7.5.3 or later, which addresses the vulnerability.
Who is affected by CVE-2025-3924?
CVE-2025-3924 affects users of the PeproDev Ultimate Profile Solutions plugin for WordPress versions between 1.9.1 and 7.5.2.
What type of vulnerability is CVE-2025-3924?
CVE-2025-3924 is an unauthorized access vulnerability that allows attackers to exploit a publicly exposed reset-password endpoint.
What are the potential impacts of CVE-2025-3924?
The impacts of CVE-2025-3924 may include exposure of user account data and potential account compromise due to unauthorized access.