CVE-2025-14975: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14975 is an unauthenticated arbitrary password reset vulnerability in the Custom Login Page Customizer WordPress plugin before version 2.5.4. The flaw allows an unauthenticated attacker to reset the password of any WordPress user — including administrators — by knowing only their username, thereby gaining full account access. It was publicly disclosed on January 8, 2026, and assigned a CVSS v3.1 base score of 8.1 (High) (WPScan, Red Hat).

Technical details

The vulnerability is classified as CWE-269 (Improper Privilege Management) and stems from a broken password reset workflow within the plugin (WPScan). When the plugin's "Custom Password Fields" feature is enabled (alongside WordPress's "Anyone can register" setting), the reset process fails to properly validate the reset key, allowing an attacker to supply an arbitrary key value and complete the password reset flow without possessing a legitimate token. The attack requires no authentication and no user interaction, but does require the target site to have the plugin's custom password fields feature enabled and user registration allowed — conditions that represent the "High" attack complexity rating. A public proof-of-concept Python script has been published by the original researcher, Drew Webber (mcdruid), demonstrating the full exploit chain in three HTTP requests (WPScan).

Impact

Successful exploitation grants an unauthenticated attacker complete control over any targeted WordPress user account, including administrator accounts. With administrator access, an attacker can install malicious plugins, modify site content, exfiltrate sensitive data stored in the WordPress database (including user credentials and personal information), and potentially pivot to the underlying server infrastructure. The confidentiality, integrity, and availability impacts are all rated High, reflecting the potential for full WordPress installation compromise (WPScan, Red Hat).

Exploitability

A working proof-of-concept Python script is publicly available via WPScan, demonstrating exploitation in just a few HTTP requests (WPScan). As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation or threat actor attribution. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.005% (0.000050), indicating a currently low probability of widespread exploitation (Red Hat).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Custom Login Page Customizer plugin (versions before 2.5.4) using tools like WPScan, Shodan, or by inspecting page source for plugin references. Confirm that user registration is enabled (/wp-login.php?action=register is accessible) and that the plugin's "Custom Password Fields" feature is active.
  2. Identify target username: Enumerate valid usernames via WordPress's default author archive (/?author=1), the REST API (/wp-json/wp/v2/users), or the login error messages at /wp-login.php.
  3. Initiate password reset: Send a POST request to /wp-login.php?action=lostpassword with the target username and an arbitrary reset key (e.g., hacked) in the user_pass field.
  4. Access reset link with forged key: Send a GET request to /wp-login.php?action=rp&key=hacked&login=<username> using the same session, bypassing proper key validation due to the plugin's flawed reset logic.
  5. Set new password: Send a POST request to /wp-login.php?action=resetpass with the desired new password and the forged rp_key=hacked, completing the password reset.
  6. Authenticate: Log in to the WordPress admin panel (/wp-admin) using the target username and the newly set password, achieving full account takeover (WPScan).

Indicators of compromise

  • Network: Multiple POST requests to /wp-login.php?action=lostpassword from the same IP address targeting different usernames in rapid succession; GET requests to /wp-login.php?action=rp with non-standard or short/predictable key parameter values (e.g., hacked, test, reset).
  • Logs: WordPress access logs showing a sequence of requests: POST /wp-login.php?action=lostpassword → GET /wp-login.php?action=rp&key=<arbitrary>&login=<username> → POST /wp-login.php?action=resetpass from the same session/IP without a preceding legitimate password reset email flow.
  • Logs: WordPress authentication logs showing successful admin logins from unfamiliar IP addresses or geographic locations shortly after the above request pattern.
  • File System: New or modified plugin files, themes, or PHP webshells in the WordPress installation directory following a successful account takeover.
  • WordPress Admin: Unexpected new administrator accounts created, plugin installations, or changes to site settings (e.g., siteurl, admin_email) in the WordPress options table (WPScan).

Mitigation and workarounds

The vendor has released a fix in Custom Login Page Customizer version 2.5.4; all users should upgrade immediately (WPScan). As a temporary workaround prior to patching, administrators should disable the plugin's "Custom Password Fields" feature or disable the plugin entirely. Additionally, disabling open user registration (Anyone can register) in WordPress general settings removes a prerequisite condition for exploitation. Network-level controls such as WAF rules blocking anomalous sequences of requests to wp-login.php reset endpoints can provide additional defense-in-depth.

Community reactions

The vulnerability was discovered and reported by researcher Drew Webber (mcdruid) and published by WPScan on January 8, 2026 (WPScan). It was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of January 5–11, 2026. Social media activity was observed on Bluesky and Mastodon (via TheHackerWire), and a technical write-up was published by Infinit Security (Infinit Security). Community reaction has been moderate, consistent with a plugin-specific vulnerability affecting sites with specific configuration requirements.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management