
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14996 is a privilege escalation via account takeover vulnerability in the AS Password Field In Default Registration Form plugin for WordPress. The flaw affects all versions up to and including 2.0.0 and allows unauthenticated attackers to change the password of any WordPress user, including administrators, thereby gaining full account access. It was published on January 6, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, NVD).
The root cause is classified as CWE-639: Authorization Bypass Through User-Controlled Key — the plugin fails to properly validate a user's identity before processing a password update request, allowing an attacker to supply an arbitrary user identifier (e.g., user ID or username) as a key to target any account (Wordfence). The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable remotely. The vulnerable code path can be reviewed in the plugin source at version 2.0.0 (Plugin Source). No public proof-of-concept exploit code has been identified at this time (Wordfence).
Successful exploitation grants an unauthenticated attacker the ability to reset the password of any WordPress user account, including site administrators, resulting in complete account takeover and full site compromise. An attacker with administrator-level access can install malicious plugins or themes, exfiltrate sensitive data, deface the site, create persistent backdoor accounts, and pivot to other systems or services connected to the WordPress environment. All three security pillars — confidentiality, integrity, and availability — are rated as high impact (Wordfence, NVD).
As of the time of reporting, no public proof-of-concept exploit code has been published and there is no confirmed evidence of in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.074%, indicating a currently low probability of exploitation in the near term (Feedly). However, the zero-authentication requirement and critical CVSS score make it a high-priority target if exploitation tooling is developed.
/wp-content/plugins/as-password-field-in-default-registration-form/)./wp-json/wp/v2/users) or login error messages to identify administrator accounts./wp-admin) using the target account's username and the newly set password, achieving full administrative access (Wordfence, Plugin Source).wp-login.php) showing successful admin logins from new or foreign IP addresses; server access logs with POST requests to plugin-specific endpoints without a valid session cookie or nonce.No patched version of the AS Password Field In Default Registration Form plugin has been confirmed as available; the vulnerability affects all versions up to and including 2.0.0 (Wordfence). Immediate recommended actions:
Wordfence, the CNA that assigned and disclosed this CVE, published the vulnerability details in their threat intelligence portal on January 6, 2026 (Wordfence). The vulnerability was highlighted in Wordfence's weekly WordPress vulnerability report for the week of January 5–11, 2026 (Wordfence Blog). It was also referenced in the CISA vulnerability bulletin for the week of January 5, 2026, and received coverage from security aggregators including TheHackerWire and Infinit Security (CISA Bulletin, Infinit Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."