External risk intelligence

WordPress CRM Memberships Plugin Password Reset Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-13313

The vulnerability affects a WordPress plugin, which is a type of software commonly deployed as part of public-facing web applications. The vulnerable endpoints (AJAX actions) are reachable over the network and intended for interaction within the web application, making them accessible to any visitor if the site is public.

Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security issue has been identified in a WordPress plugin used for membership management, which could allow unauthorized individuals to reset user passwords. This vulnerability is critical because it enables unauthenticated attackers to gain access to user accounts, potentially impacting sensitive information or services. The main concern is confirming if this plugin is in use and exposed to external access.

  • Unauthorized password resets can compromise user accounts.
  • Protects against unauthorized access and potential data breaches.
  • Assess plugin usage and exposure to confirm relevance.

Attack Path

How an attacker could exploit the issue

An attacker could begin by enumerating user email addresses exposed through an unauthenticated endpoint. With an email address in hand, they could then use another unauthenticated endpoint to reset the target user's password, gaining unauthorized access to their account.

  • Unauthenticated access to user emails.
  • Password reset via AJAX action.
  • Unauthorized account access and privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

The CRM Memberships plugin for WordPress has a vulnerability that could allow unauthenticated attackers to reset user passwords. This is possible when supported by the advisory's conditions, such as when an attacker can obtain or guess a target user's email address. The plugin also exposes a way to list user email addresses without authentication, which could aid attackers.

  • User account access at risk.
  • Unauthenticated password resets are possible.
  • Unauthorized access to user accounts.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security teams should identify all WordPress sites using the CRM Memberships plugin to determine exposure and business criticality. Coordination with application owners or platform teams will be necessary to plan remediation, potentially involving vendor engagement for a fix or implementing compensating controls.

  • Site administrators and application owners.
  • Verify plugin usage and user email accessibility.
  • Plan remediation or implement access restrictions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the CRM Memberships plugin for WordPress?

This plugin is a tool designed for website administrators to manage member registrations, subscriptions, and user access levels directly within a WordPress environment. It provides functionality to handle customer data and membership status, often integrating features like AJAX-based interactions to improve user experience on membership portals.

How does CVE-2025-13313 affect account security?

The vulnerability involves a failure to verify user identity, classified as CWE-862 (Missing Authorization). Specifically, the plugin does not check if a visitor has permission to perform sensitive tasks. This allows an unauthorized person to invoke an internal password reset function, effectively letting them change the password for any user account if they know the associated email address.

Do I need to be logged in to trigger this vulnerability?

No, you do not need an account or valid credentials to trigger this issue. The vulnerability stems from unprotected AJAX endpoints. The bug is triggered when an attacker interacts with these specific backend functions, and it does not require a legitimate session. Simply accessing these endpoints, which the plugin fails to guard, is sufficient to initiate the unauthorized password reset process.

Is my site at risk according to Halo Surface Signal?

Yes, if your site uses this plugin and is accessible to the public, Halo Surface Signal identifies it as a likely target. Because the vulnerable AJAX actions are reachable over the network, any external visitor can interact with these endpoints. Sites that are publicly exposed are at higher risk than those restricted to internal, private networks.

When should I take action to secure my WordPress installation?

You should act immediately by locating any WordPress instances running the CRM Memberships plugin. First, confirm if the plugin is currently active on your site. If found, consult your site’s administrative dashboard or plugin developer resources to verify if you are running an affected version and coordinate with your platform team to apply updates or implement access restrictions to disable the vulnerable endpoints.

References