CVE Database
/

CVE-2025-15030

Back to search

CVE-2025-15030

Published: Feb 2, 2026

Modified: Feb 2, 2026

PUBLISHED

Description

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

VendorProductVersions

Unknown

User Profile Builder

affected
1.1.27 - < 3.15.2

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now