CVE advisoryCRITICAL
CVE-2025-13615
StreamTube Core WordPress Plugin Arbitrary Password Change Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in the StreamTube Core WordPress plugin allows unauthenticated attackers to change user passwords and potentially take over administrator accounts if registration password fields are enabled. This could lead to unauthorized access and control of the WordPress site.