Impact
The FS Registration Password plugin fails to verify a user’s identity before updating a password, allowing an unauthenticated attacker to change the passwords of any user, including administrators. This flaw effectively grants the attacker full access to affected accounts without requiring initial authentication.
Affected Systems
All versions of the FS Registration Password plugin by FSylum up to and including 1.0.1 are vulnerable. No specific user or installation constraints are listed, so any WordPress site running the plugin in these versions could be affected.
Risk and Exploitability
The CVSS score of 9.8 reflects a severe risk, while the EPSS score of < 1% indicates that the vulnerability is currently considered unlikely to be widely exploited. The flaw is not listed in the CISA KEV catalog. The attack can be performed remotely by sending an unauthenticated HTTP request to the plugin’s password‐reset functionality, which bypasses all authentication checks. If exploited, the attacker could obtain unrestricted access to the site, modify content, install additional malware, or compromise other systems linked to the site.
OpenCVE Enrichment