External risk intelligence

Truelysell Core WordPress Plugin Arbitrary Password Change Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-10742

The vulnerability exists in a WordPress plugin. WordPress sites are commonly deployed as public-facing web applications. Because the plugin functionality is exposed via a shortcode on a page, it is accessible to anyone who can navigate to that page on the public internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Truelysell Core WordPress plugin allows unauthenticated attackers to change user passwords, potentially leading to administrator account takeover. The exploit requires knowledge of a specific page containing a shortcode, but if present, it could allow unauthorized access and control of WordPress sites.

  • Unauthenticated attackers can change user passwords.
  • Confirms plugin relevance and exposure on WordPress sites.
  • Assess exposure and review plugin usage.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can gain administrative access to a WordPress site by exploiting a vulnerability in the Truelysell Core plugin. This is possible if the attacker can identify a page containing a specific shortcode, allowing them to bypass authorization checks and change user passwords, including those of administrators.

  • No authentication needed to start.
  • Bypass authorization to change passwords.
  • Risk of administrator account takeover.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could change user passwords and gain control of administrator accounts on WordPress sites running the Truelysell Core plugin. This is possible when the attacker can identify a page containing the 'truelysell_edit_staff' shortcode, allowing them to bypass authorization and access system resources.

  • WordPress administrator accounts at risk.
  • Attacker could change user passwords.
  • Potential takeover of affected sites.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Truelysell Core WordPress plugin, allowing unauthenticated arbitrary password changes, is a critical risk for any organization using the plugin. The primary responsibility for addressing this will likely fall on the teams managing the WordPress instances and the applications hosted on them, such as Web Application Teams or Platform Operations. The first crucial step is to identify all WordPress sites utilizing the Truelysell Core plugin, determine their exposure (especially if publicly accessible), and confirm ownership to initiate a coordinated response.

  • Application owners should own the issue.
  • Verify plugin presence and reachability.
  • Plan remediation during the next maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Truelysell Core plugin?

Truelysell Core is a WordPress plugin typically bundled with the Truelysell service booking theme. It provides backend functionality for managing staff and booking services on a WordPress site. Users often install this plugin to enable marketplace or service-based features within their web presence.

What does CWE-639 mean for CVE-2025-10742?

This vulnerability is classified as CWE-639, or Authorization Bypass Through User-Controlled Key. In plain terms, the plugin fails to properly verify if a user has permission to modify specific data. Because of this flaw, the system blindly trusts requests to change passwords, allowing an attacker to manipulate user account credentials without needing prior authorization.

How is this vulnerability triggered?

The flaw is triggered when an attacker interacts with a specific page on the site that contains the 'truelysell_edit_staff' shortcode. If that shortcode is not present on any page, or if the page is inaccessible, the trigger path is blocked. Simply having the plugin installed is not enough; the specific shortcode must be active and reachable for the exploit to function.

Is my site at risk according to Halo Surface Signal?

Yes, if you use this plugin, your risk is considered likely. Halo Surface Signal notes that because WordPress sites are generally public-facing and this vulnerability relies on an accessible shortcode, an attacker on the internet can potentially target your installation. If your site is on the public web, it is within the reach of this threat.

How do I respond to this vulnerability?

Start by identifying every WordPress instance in your environment where the Truelysell Core plugin is active. Once you have an inventory, determine if any of these sites utilize the 'truelysell_edit_staff' shortcode. If the plugin is unnecessary, removing it is the safest course of action. Otherwise, coordinate with your technical team to plan for updates or security adjustments during your next maintenance window.

References