Impact
The AS Password Field In Default Registration Form plugin for WordPress is vulnerable because it fails to verify a user's identity before allowing a password change. An attacker can therefore change the password of any user, including administrators, without authenticating. The vulnerability results in unauthorized access to user accounts and is classified as CWE‑639.
Affected Systems
This issue affects the Aksharsoft Solutions "AS Password Field In Default Registration Form" WordPress plugin, all releases up to and including version 2.0.0. WordPress sites that have any of these versions installed are at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical level of risk. The EPSS score of less than 1% suggests the probability of exploitation is low, but the high severity makes this a top priority for remediation. The likely attack vector is a web‑based POST request to the plugin’s password update endpoint, executed by an unauthenticated user.
OpenCVE Enrichment