CVE-2025-4607: Empoweringprowebsite Psw Front-End Login & Registration
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function. This is due to the use of a weak, low-entropy OTP mechanism in the forget() function. This makes it possible for unauthenticated attackers to initiate a password reset for any user, including administrators, and elevate their privileges for full site takeover.
Affected products
- Empoweringprowebsite Psw Front-End Login & Registration: up to and including 1.12
Published 2025-05-31. Last modified 2026-06-17.