Sploitus

CVE-2025-15030

1 known exploit for CVE-2025-15030

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

Affected products
User Profile Builder
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
0.5% (40th percentile)
Weakness
CWE-269
NVD status
Deferred
Published
2026-02-02
CVE-2025-15030 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-15030

Proof-of-concept code and exploit modules indexed by Sploitus