
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14975 is an unauthenticated arbitrary password reset vulnerability in the Custom Login Page Customizer WordPress plugin before version 2.5.4. The flaw allows an unauthenticated attacker to reset the password of any WordPress user — including administrators — by knowing only their username, thereby gaining full account access. It was publicly disclosed on January 8, 2026, and assigned a CVSS v3.1 base score of 8.1 (High) (WPScan, Red Hat).
The vulnerability is classified as CWE-269 (Improper Privilege Management) and stems from a broken password reset workflow within the plugin (WPScan). When the plugin's "Custom Password Fields" feature is enabled (alongside WordPress's "Anyone can register" setting), the reset process fails to properly validate the reset key, allowing an attacker to supply an arbitrary key value and complete the password reset flow without possessing a legitimate token. The attack requires no authentication and no user interaction, but does require the target site to have the plugin's custom password fields feature enabled and user registration allowed — conditions that represent the "High" attack complexity rating. A public proof-of-concept Python script has been published by the original researcher, Drew Webber (mcdruid), demonstrating the full exploit chain in three HTTP requests (WPScan).
Successful exploitation grants an unauthenticated attacker complete control over any targeted WordPress user account, including administrator accounts. With administrator access, an attacker can install malicious plugins, modify site content, exfiltrate sensitive data stored in the WordPress database (including user credentials and personal information), and potentially pivot to the underlying server infrastructure. The confidentiality, integrity, and availability impacts are all rated High, reflecting the potential for full WordPress installation compromise (WPScan, Red Hat).
A working proof-of-concept Python script is publicly available via WPScan, demonstrating exploitation in just a few HTTP requests (WPScan). As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation or threat actor attribution. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.005% (0.000050), indicating a currently low probability of widespread exploitation (Red Hat).
/wp-login.php?action=register is accessible) and that the plugin's "Custom Password Fields" feature is active./?author=1), the REST API (/wp-json/wp/v2/users), or the login error messages at /wp-login.php./wp-login.php?action=lostpassword with the target username and an arbitrary reset key (e.g., hacked) in the user_pass field./wp-login.php?action=rp&key=hacked&login=<username> using the same session, bypassing proper key validation due to the plugin's flawed reset logic./wp-login.php?action=resetpass with the desired new password and the forged rp_key=hacked, completing the password reset./wp-admin) using the target username and the newly set password, achieving full account takeover (WPScan)./wp-login.php?action=lostpassword from the same IP address targeting different usernames in rapid succession; GET requests to /wp-login.php?action=rp with non-standard or short/predictable key parameter values (e.g., hacked, test, reset).POST /wp-login.php?action=lostpassword → GET /wp-login.php?action=rp&key=<arbitrary>&login=<username> → POST /wp-login.php?action=resetpass from the same session/IP without a preceding legitimate password reset email flow.siteurl, admin_email) in the WordPress options table (WPScan).The vendor has released a fix in Custom Login Page Customizer version 2.5.4; all users should upgrade immediately (WPScan). As a temporary workaround prior to patching, administrators should disable the plugin's "Custom Password Fields" feature or disable the plugin entirely. Additionally, disabling open user registration (Anyone can register) in WordPress general settings removes a prerequisite condition for exploitation. Network-level controls such as WAF rules blocking anomalous sequences of requests to wp-login.php reset endpoints can provide additional defense-in-depth.
The vulnerability was discovered and reported by researcher Drew Webber (mcdruid) and published by WPScan on January 8, 2026 (WPScan). It was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of January 5–11, 2026. Social media activity was observed on Bluesky and Mastodon (via TheHackerWire), and a technical write-up was published by Infinit Security (Infinit Security). Community reaction has been moderate, consistent with a plugin-specific vulnerability affecting sites with specific configuration requirements.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."