Description
The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsd_plugin_control() function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to reactivate previously deactivated plugins after accessing the "Profiler" page.
Published: 2025-06-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Plugin Reactivation
Action: Apply Patch
AI Analysis

Impact

The Profiler – What Slowing Down Your WP plugin contains a missing authorization check in the wpsd_plugin_control() function in all releases up to and including 1.0.0. Because of this, anyone able to reach the Profiler page can reactivate plugins that have been previously disabled without needing to be logged in. This unexpected ability to alter the active plugin set exposes the site to potential integrity or availability problems, especially if a reactivated plugin has its own vulnerabilities or exploits.

Affected Systems

This issue affects the Switcorp Profiler – What Slowing Down Your WP plugin for WordPress, specifically all versions up to 1.0.0. Owners of sites using this plugin should review the plugin version in use and note that the security flaw is present in these releases.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk, while the EPSS score of less than 1% suggests that the vulnerability is unlikely to be exploited at present. The flaw is not listed in CISA KEV, further indicating limited reported exploitation. An attacker would need only browser access to the Profiler page to trigger the vulnerability, implying a web-based attack vector that bypasses authentication. Once a plugin is reactivated, additional risks may arise depending on the plugin’s own security posture.

Generated by OpenCVE AI on April 21, 2026 at 20:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Profiler – What Slowing Down Your WP plugin to the latest release that includes the missing capability check.
  • If an updated version is not available, immediately deactivate and remove the Profiler plugin from the site.
  • As a temporary measure, restrict access to the Profiler page so that only authenticated administrators can view it, for example by adding a capability check or using an access control plugin.

Generated by OpenCVE AI on April 21, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17368 The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsd_plugin_control() function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to reactivate previously deactivated plugins after accessing the "Profiler" page.
History

Mon, 09 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 07 Jun 2025 04:30:00 +0000

Type Values Removed Values Added
Description The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsd_plugin_control() function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to reactivate previously deactivated plugins after accessing the "Profiler" page.
Title Profiler – What Slowing Down Your WP <= 1.0.0 - Missing Authentication to Unauthenticated Arbitrary Plugin Reactivation via State Restoration
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:09:20.507Z

Reserved: 2025-06-06T16:14:55.840Z

Link: CVE-2025-5814

cve-icon Vulnrichment

Updated: 2025-06-09T15:11:47.386Z

cve-icon NVD

Status : Deferred

Published: 2025-06-07T05:15:24.913

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-5814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T20:30:27Z

Weaknesses