The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handel_ajax_req() function in versions 1.9.1 to 7.5.2. This makes it possible for unauthenticated attackers to update arbitrary user's metadata which can be leveraged to block an administrator from accessing their site when wp_capabilities is set to 0.
Metrics
Affected Vendors & Products
References
History
Wed, 07 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 07 May 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handel_ajax_req() function in versions 1.9.1 to 7.5.2. This makes it possible for unauthenticated attackers to update arbitrary user's metadata which can be leveraged to block an administrator from accessing their site when wp_capabilities is set to 0. | |
Title | PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req Function | |
Weaknesses | CWE-285 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-05-07T01:43:08.850Z
Updated: 2025-05-07T14:03:00.745Z
Reserved: 2025-04-24T12:48:36.794Z
Link: CVE-2025-3921

Updated: 2025-05-07T13:47:41.881Z

Status : Awaiting Analysis
Published: 2025-05-07T03:15:18.573
Modified: 2025-05-07T14:13:20.483
Link: CVE-2025-3921

No data.