S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 20, 2025

CVE-2025-47646 Scanner

CVE-2025-47646 Scanner - Missing Authorization vulnerability in PSW Front-end Login & Registration

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-47646
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
PSW Front-end Login & Registrationby Gilblas Ngunte Possi
0
Updated Aug 22, 2026View on NVD →
Detail

The PSW Front-end Login & Registration plugin is commonly used on WordPress sites to allow users to register and log in via front-end forms. It is widely adopted due to its easy integration into WordPress environments, simplifying user access management for administrators. Installed by website owners aiming to enhance user experience, this plugin facilitates a streamlined login and registration process. Many businesses and personal sites utilize this plugin to boost their site’s interactivity and user engagement. As a WordPress plugin, it also allows for customization through WordPress themes and additional plugins, making it versatile for a range of website types. The plugin's ability to handle user credentials makes it a crucial tool for sites requiring visitor authentication.

Missing Authorization vulnerabilities occur when applications fail to restrict user access to certain areas or actions within the system. This specific vulnerability affects the PSW Front-end Login & Registration plugin, which lacks proper authorization checks during the password recovery process. Unauthenticated attackers can exploit this flaw, potentially gaining unauthorized access to user accounts. This issue arises from the plugin not verifying user credentials adequately, allowing attackers to bypass account security measures. Such vulnerabilities are critical as they can result in unauthorized data access or privilege escalation. Addressing these vulnerabilities often involves tightening account recovery workflows and implementing robust authentication checks.

The vulnerability details indicate a flaw in the password recovery mechanism of the PSW Front-end Login & Registration plugin. Through crafted requests to the endpoint responsible for password recovery, attackers can manipulate form inputs. Specifically, the endpoint `/wp-admin/admin-ajax.php` processes requests without confirming the legitimacy of the requester. The use of predictable request tokens and insufficient validation checks allow attackers to abuse this process, creating a vector for unauthorized account access. The plugin improperly handles authentication tokens, failing to enforce access controls. Exploitation involves manipulating the process to retrieve activation links, leading to a potential security breach.

Exploiting this vulnerability could allow unauthorized users to access sensitive user accounts on WordPress sites. Affected systems risk data breaches, unauthorized data manipulation, and potential site defacement. Additionally, exploitation may lead to further network compromises, as attackers could pivot from compromised accounts to elevate privileges or gain further unauthorized access. Such vulnerabilities commonly attract automated attacks, opening a path for mass exploitation across numerous platforms. Moreover, user trust in the affected site could diminish substantially, leading to reputational damage.

REFERENCES

Solution Advice
  • Implement proper authorization checks to ensure only authenticated users can initiate password recovery.
  • Introduce captcha verification during the password recovery process to prevent automated attacks.
  • Regularly audit plugins and update them to the latest secure versions to mitigate known vulnerabilities.
  • Enforce password complexity requirements and multifactor authentication for users to enhance account security.
  • Monitor user account activities for irregular actions and respond to potential security incidents promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.