CVE-2025-14998

CRITICAL EXPLOITED

Branda WordPress <3.4.24 - Privilege Escalation

Title source: llm

Description

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

Exploits (1)

nomisec WORKING POC 1 stars
by KTN1990 · remote
https://github.com/KTN1990/CVE-2025-14998

Scores

CVSS v3 9.8
EPSS 0.0005
EPSS Percentile 16.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2026-01-02
CWE
CWE-639
Status published
Products (1)
wpmudev/Branda – White Label & Branding, Free Login Page Customizer < 3.4.24
Published Jan 02, 2026
Tracked Since Feb 18, 2026