Impact
The PSW Front‑end Login & Registration plugin has a weak password recovery mechanism. An attacker can trigger the recovery flow and reset any user’s password without proper authentication, effectively bypassing the plugin’s intended security controls. This flaw permits unauthorized access to the WordPress site and its sensitive data.
Affected Systems
Any WordPress installation that has the PSW Front‑end Login & Registration plugin version 1.13 or earlier. The plugin is developed by Gilblas Ngunte Possi under the codename PSW Front‑end Login & Registration.
Risk and Exploitability
The vulnerability is scored 9.8 on the CVSS 3.1 scale, indicating critical severity. The EPSS score of 22 % shows a high probability of exploitation. It is not listed in the CISA KEV catalog. An attacker can exploit the flaw via the publicly accessible password recovery page by submitting a recovery request for any user. No special privileges or privileged code execution are required to use the vulnerability.
OpenCVE Enrichment
EUVD