
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14998 is a privilege escalation via account takeover vulnerability in the Branda (White Label & Branding) plugin for WordPress. The flaw affects all versions up to and including 3.4.24 and allows unauthenticated attackers to reset arbitrary user passwords — including administrator accounts — due to improper identity validation before processing password update requests. It was published on January 2, 2026, with the CVE received from Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, NVD).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the plugin's password update logic in inc/modules/login-screen/signup-password.php (line 24) does not properly verify the requesting user's identity before applying the password change, allowing an attacker to supply an arbitrary user identifier and overwrite that account's password (NVD, Wordfence). The attack vector is network-accessible, requires no authentication, no user interaction, and low complexity, making it trivially exploitable against any WordPress site running the vulnerable plugin version. A public proof-of-concept is available on GitHub (PoC GitHub).
Successful exploitation allows an unauthenticated attacker to take over any WordPress user account, including site administrators, by resetting their password without authorization. Once administrative access is obtained, an attacker can modify site content, install malicious plugins or themes, create additional backdoor administrator accounts for persistence, exfiltrate sensitive data, or fully compromise the integrity and availability of the WordPress installation. The confidentiality, integrity, and availability impacts are all rated High (Wordfence, Feedly).
A public proof-of-concept exploit is available on GitHub (added March 2, 2026) (PoC GitHub). The vulnerability has also been referenced on Sploitus (PacketStorm exploit ID 213483). As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.07% (0.0007), indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. It is detectable by Qualys scanner (detection ID 733559) (Feedly).
inc/modules/login-screen/signup-password.php)./wp-login.php)./wp-admin/admin-ajax.php or plugin-specific routes) from unauthenticated or unknown IP addresses; unusual login attempts to WordPress admin accounts from new IP addresses shortly after such requests.wp-login.php) showing successful logins from unfamiliar IPs for administrator accounts; access logs showing POST requests to Branda plugin endpoints without a valid session cookie.wp-config.php.wp_users table with unexpected timestamps.Update the Branda plugin to a version newer than 3.4.24, which includes the fix applied in changeset 3429115 (WordPress Trac). If an immediate update is not possible, temporarily deactivate the Branda plugin to eliminate the attack surface. After patching, review all administrator account activity logs for unauthorized access and reset passwords for all administrative and sensitive user accounts as a precautionary measure. Wordfence users (both free and premium) should ensure their firewall rules are up to date for additional protection (Wordfence).
Wordfence published the vulnerability details and assigned the CVE, highlighting it in their weekly WordPress vulnerability report for December 15, 2025 – January 4, 2026 (Wordfence Blog). The vulnerability was noted on social media platforms including Bluesky and Mastodon (TheHackerWire), and was included in CISA's vulnerability bulletin for the week of December 29, 2025. Community interest was moderate, with the PoC being tracked on tonyharris.io's PoC Week digest for January 12, 2026.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."