CVE-2025-15096
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15096 is a privilege escalation vulnerability via account takeover in the 'Videospirecore Theme Plugin' for WordPress. The flaw affects all versions up to and including 1.0.6, and stems from the plugin failing to properly validate a user's identity before allowing updates to account details such as email addresses. It was published on February 11, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat CVE, Wordfence).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the plugin does not verify that the requesting user owns or is authorized to modify the target account before processing email update requests. An authenticated attacker with Subscriber-level access or higher can supply an arbitrary user identifier in the request to overwrite any user's email address, including that of an administrator. Once the email is changed, the attacker can trigger WordPress's standard password reset flow to the attacker-controlled address, completing the account takeover without any additional privileges or user interaction (Red Hat CVE, Wordfence).

Impact

Successful exploitation grants an attacker full administrative control over the WordPress installation. With administrator access, the attacker can read sensitive site data, modify or delete content, install malicious plugins or themes, create backdoor accounts, and potentially pivot to the underlying hosting infrastructure. All confidentiality, integrity, and availability dimensions are rated High in the CVSS scoring (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.039%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. A Nuclei detection template pull request was submitted to the ProjectDiscovery repository, which may lower the barrier for automated scanning (Wordfence, Nuclei Templates PR).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Videospirecore Theme Plugin version 1.0.6 or earlier using tools such as WPScan or Shodan with WordPress fingerprinting.
  2. Obtain low-privilege account: Register or obtain credentials for a Subscriber-level (or higher) account on the target WordPress site.
  3. Identify target user ID: Enumerate WordPress user IDs for administrator accounts via the WordPress REST API (/wp-json/wp/v2/users) or other enumeration techniques.
  4. Craft malicious request: Send an authenticated HTTP request to the plugin's email-update endpoint, supplying the administrator's user ID as the target and an attacker-controlled email address as the new value, bypassing the missing authorization check.
  5. Trigger password reset: Use WordPress's built-in password reset functionality (/wp-login.php?action=lostpassword) for the administrator account; the reset link is delivered to the attacker-controlled email.
  6. Complete account takeover: Follow the password reset link, set a new password, and log in as the administrator to achieve full site compromise (Red Hat CVE, Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to the Videospirecore plugin's user-update endpoint with user IDs not matching the authenticated session's own user ID; multiple rapid email-change events in wp_users or WordPress audit logs.
  • Logs: Password reset requests (/wp-login.php?action=lostpassword) for administrator accounts shortly after an email address change event.
  • File System: Presence of newly installed plugins or themes not authorized by site administrators; unexpected new administrator-level user accounts in wp_users.
  • Network: Outbound connections from the WordPress server to unfamiliar external hosts following a successful account takeover, potentially indicating backdoor installation or data exfiltration.

Mitigation and workarounds

As of the disclosure date, no patched version of the Videospirecore Theme Plugin has been confirmed available. Site administrators should immediately deactivate and remove the plugin from all WordPress installations running version 1.0.6 or earlier. User roles should be audited and restricted to the minimum necessary permissions; review all accounts for unauthorized email address changes and revoke any suspicious sessions. Monitor WordPress authentication and user-update logs for anomalous activity, and apply a patch as soon as the vendor releases an updated version (Red Hat CVE, Wordfence).

Community reactions

Wordfence included CVE-2025-15096 in its weekly WordPress vulnerability digest for the period of February 9–15, 2026, flagging it as a notable privilege escalation issue (Wordfence). RedPacket Security also published an alert and shared it on Mastodon, contributing to broader community awareness (RedPacket Security). A Nuclei template pull request was opened to enable automated detection, indicating active interest from the security research community (Nuclei Templates PR).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management