CRITICAL
fsylum
CVE published 2026-01-06
CVE-2025-15001
The FS Registration Password plugin for WordPress has a critical vulnerability allowing unauthenticated attackers to change arbitrary user passwords, including administrators, due to improper identity validation. This vulnerability, tracked as CVE-2025-15001, has a CVSS score of 9.8, indicating a high severity level. The plugin's failure to validate user identity prior to updating passwords enables attack [truncated]