
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15096 is a privilege escalation vulnerability via account takeover in the 'Videospirecore Theme Plugin' for WordPress. The flaw affects all versions up to and including 1.0.6, and stems from the plugin failing to properly validate a user's identity before allowing updates to account details such as email addresses. It was published on February 11, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat CVE, Wordfence).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the plugin does not verify that the requesting user owns or is authorized to modify the target account before processing email update requests. An authenticated attacker with Subscriber-level access or higher can supply an arbitrary user identifier in the request to overwrite any user's email address, including that of an administrator. Once the email is changed, the attacker can trigger WordPress's standard password reset flow to the attacker-controlled address, completing the account takeover without any additional privileges or user interaction (Red Hat CVE, Wordfence).
Successful exploitation grants an attacker full administrative control over the WordPress installation. With administrator access, the attacker can read sensitive site data, modify or delete content, install malicious plugins or themes, create backdoor accounts, and potentially pivot to the underlying hosting infrastructure. All confidentiality, integrity, and availability dimensions are rated High in the CVSS scoring (Red Hat CVE).
No public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.039%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. A Nuclei detection template pull request was submitted to the ProjectDiscovery repository, which may lower the barrier for automated scanning (Wordfence, Nuclei Templates PR).
/wp-json/wp/v2/users) or other enumeration techniques./wp-login.php?action=lostpassword) for the administrator account; the reset link is delivered to the attacker-controlled email.wp_users or WordPress audit logs./wp-login.php?action=lostpassword) for administrator accounts shortly after an email address change event.wp_users.As of the disclosure date, no patched version of the Videospirecore Theme Plugin has been confirmed available. Site administrators should immediately deactivate and remove the plugin from all WordPress installations running version 1.0.6 or earlier. User roles should be audited and restricted to the minimum necessary permissions; review all accounts for unauthorized email address changes and revoke any suspicious sessions. Monitor WordPress authentication and user-update logs for anomalous activity, and apply a patch as soon as the vendor releases an updated version (Red Hat CVE, Wordfence).
Wordfence included CVE-2025-15096 in its weekly WordPress vulnerability digest for the period of February 9–15, 2026, flagging it as a notable privilege escalation issue (Wordfence). RedPacket Security also published an alert and shared it on Mastodon, contributing to broader community awareness (RedPacket Security). A Nuclei template pull request was opened to enable automated detection, indicating active interest from the security research community (Nuclei Templates PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."