CVE-2025-15030: Unknown User Profile Builder

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

Affected products

  • Unknown User Profile Builder: from 1.1.27, before 3.15.2 (fixed in 3.15.2)

Published 2026-02-02. Last modified 2026-06-17.