External risk intelligence

WordPress AS Password Field Plugin Account Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-14996

The vulnerability resides in a WordPress plugin that modifies the user registration form. WordPress registration forms are public-facing by design and intended to be reachable by internet users to create accounts, making the vulnerable component directly exposed on the public internet.

Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A WordPress plugin designed to manage passwords in default registration forms contains a critical flaw allowing attackers to take over any user account, including administrators, by changing their passwords. This vulnerability is accessible to unauthenticated attackers over the network.

  • Any account can be taken over by changing its password.
  • This affects public-facing WordPress registration forms.
  • Confirm relevance and exposure to protect administrative access.

Attack Path

How an attacker could exploit the issue

An attacker can compromise accounts by exploiting a weakness in the AS Password Field In Default Registration Form plugin for WordPress. This vulnerability allows anyone on the internet to reset any user's password, including administrators, without needing to log in or even know a valid username. Successful exploitation could lead to a full takeover of affected WordPress sites.

  • Unauthenticated access to registration form.
  • Changing any user's password.
  • Full account takeover risk.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could take over any user account, including administrators, by changing passwords without proper identity verification. This could impact user accounts and their associated data when supported by the advisory.

  • User accounts and their data.
  • Unauthenticated password changes.
  • Account takeover and data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

For this critical vulnerability affecting the AS Password Field In Default Registration Form plugin for WordPress, the primary ownership likely falls to the application owners responsible for managing WordPress sites and plugins, with support from infrastructure or platform teams who manage the underlying web servers and environments. The first practical step is to identify all WordPress instances utilizing this plugin, determine their exposure (especially public-facing registration forms), and confirm the business criticality of these sites. Subsequently, accountable owners should be engaged to plan a risk-based remediation strategy.

  • Application owners should manage this issue.
  • Verify plugin usage and exposure first.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the AS Password Field In Default Registration Form plugin?

It is a WordPress plugin designed to customize or manage how password fields appear and function within the default user registration process. By modifying this core registration workflow, the plugin integrates into the public-facing signup pages that WordPress sites use to allow new users to create accounts.

What does CWE-639 mean for CVE-2025-14996?

CWE-639 refers to an Authorization Bypass Through User-Controlled Key. In the context of this CVE, it means the plugin fails to verify that the person requesting a password change is actually the owner of the account. Because the software does not properly check identity, it mistakenly trusts user input, allowing an attacker to manipulate the password for any account on the site.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by interacting with the registration form provided by the plugin. No special privileges or prior authentication are required. Notably, the vulnerability is not triggered by standard site usage or by registered users acting normally; it specifically occurs when the plugin processes malicious requests intended to overwrite account credentials without authorization.

Is my site at risk according to Halo Surface Signal?

Yes, if you use this plugin, your site is likely exposed. Halo Surface Signal identifies that because this vulnerability exists within a WordPress registration form—a component designed to be reachable by internet users—it is inherently accessible to public network traffic. Any WordPress instance running this plugin and enabling user registration is effectively facing the internet.

Do I need to remove this plugin immediately?

The first step is to audit your WordPress environments to confirm if this specific plugin is installed and active. Once identified, evaluate the necessity of the plugin against the risk of total account takeover. If the plugin is not essential, removing it is the most effective way to eliminate the risk. If it must be kept, restrict access to the registration page until you can confirm a secure state.

References