CVE-2025-3921 HIGH

CVE-2025-3921: PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req Function

Vendor Peprodev
Product PeproDev Ultimate Profile Solutions
Weakness CWE-285
Published May 7, 2025
Last update May 7, 2025

CVSS base score

8.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

What the vulnerability does

01Description

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handel_ajax_req() function in versions 1.9.1 to 7.5.2. This makes it possible for unauthenticated attackers to update arbitrary user's metadata which can be leveraged to block an administrator from accessing their site when wp_capabilities is set to 0.

Explanation of Vulnerability in Simple Terms

02Summary

PeproDev Ultimate Profile Solutions versions 1.9.1 through 7.5.2 contain an integrity vulnerability that allows unauthenticated attackers to modify data over the network without user interaction. The flaw stems from insufficient access controls (CWE-285). Affected sites should update immediately to a version newer than 7.5.2.

What an attacker can do

03Attacker Capabilities

Modify data on the site without logging in or user interaction.

Potential impact on your site

04Site Impact

Attackers can alter site content, user data, or settings without authorization.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

May 7, 2025 CVE published
May 7, 2025 Record updated

Related vulnerabilities

08Related CVE