CVE-2025-15030
CRITICAL EXPLOITEDUser Profile Builder <3.15.2 - Info Disclosure
Title source: llmDescription
The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account
Exploits (4)
github
NO CODE
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-15030
Scores
CVSS v3
9.8
EPSS
0.0002
EPSS Percentile
5.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2026-02-03
Classification
CWE
CWE-269
Status
draft
Timeline
Published
Feb 02, 2026
Tracked Since
Feb 18, 2026