External risk intelligence

StreamTube Core WordPress Plugin Arbitrary Password Change Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-13615

The vulnerability affects a WordPress plugin, which is typically deployed as a public-facing web application. Since the flaw involves user registration and authentication processes that are frequently exposed to the internet for site visitors to interact with, the attack surface is commonly internet-facing.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in a WordPress plugin that, under specific configuration conditions, could allow unauthenticated attackers to change user passwords and potentially gain control of administrator accounts. This issue affects the StreamTube Core plugin.

  • Unauthenticated users could change passwords.
  • Allows takeover of administrator accounts.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can change any user's password without needing to log in, by exploiting a flaw in how the StreamTube Core WordPress plugin handles user data. This is possible if the theme allows registration password fields to be enabled. By manipulating access to objects, an unauthenticated attacker can bypass security checks. If successful, this could lead to an attacker taking control of administrator accounts.

  • Requires registration password fields enabled.
  • Unauthenticated access to user object manipulation.
  • Potential for full administrator account takeover.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could change user passwords and take over administrator accounts if the 'registration password fields' are enabled in theme options. This allows them to bypass authorization and access system resources.

  • Administrator account access.
  • Bypass authorization to change passwords.
  • Potential account takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects the StreamTube Core plugin for WordPress. Ownership likely resides with the application owner responsible for the WordPress site, in coordination with the platform or infrastructure team managing the web server environment. The first practical step is to identify all WordPress instances using this plugin, determine if the 'registration password fields' option is enabled, and confirm internet reachability to assess risk.

  • Application owners manage the issue.
  • Verify 'registration password fields' status.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the StreamTube Core plugin?

StreamTube Core is a component designed for the StreamTube WordPress theme. It provides backend functionality for video-centric sites, often handling user profile management and registration features that allow visitors to interact with the platform.

What does CWE-639 mean for CVE-2025-13615?

CWE-639 refers to an Authorization Bypass Through User-Controlled Key. In this case, the plugin fails to verify if a user is permitted to modify a specific account's password. Because the software improperly trusts input used to identify account objects, an attacker can manipulate that data to change passwords they should not have access to.

How can an attacker trigger this vulnerability?

An attacker can exploit this if the 'registration password fields' option is active within the theme settings. This flaw cannot be triggered if these specific registration fields are disabled, as the vulnerable code path that processes the unauthorized password change request is not engaged.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a likely risk because the affected plugin operates within WordPress, a platform typically deployed as an internet-facing web application. Since the vulnerability involves registration and authentication features meant for visitor interaction, it is commonly exposed to remote network requests.

Do I need to check my WordPress site immediately?

Yes, begin by auditing your WordPress environment to identify if the StreamTube Core plugin is installed. If found, verify whether the 'registration password fields' option is enabled in your theme settings, as this is the primary condition that makes the site susceptible to unauthorized password changes.

References