CVE-2025-15001
CRITICALFS Registration Password <1.0.1 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-15001. PoCs published by r00thex.
AI-analyzed exploit summary This exploit targets CVE-2025-15001, an unauthenticated account takeover vulnerability in the 'root Registration Password' WordPress plugin (versions <= 1.0.1). The flaw allows attackers to inject a known password reset key via a crafted request to the password reset flow, then use that key to reset the target user's password.
Description
The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Exploits (1)
This exploit targets CVE-2025-15001, an unauthenticated account takeover vulnerability in the 'root Registration Password' WordPress plugin (versions <= 1.0.1). The flaw allows attackers to inject a known password reset key via a crafted request to the password reset flow, then use that key to reset the target user's password.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H