Reales WP STPT <= 2.1.2 - Authenticated (Subscriber+) Privilege Escalation via Password Update
high
The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for authenticated attackers, with subs...
- CVSS:
- 8.8
- Affected:
- up to 2.1.2
- Fix:
- No patched version reported
- Disclosed:
- May 5, 2025
CVE-2025-3610 on NVD →
Reales WP STPT <= 2.1.2 - Unauthorized User Registration
medium
The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to the 'reales_user_signup_form' AJAX action not verifying if user registration is enabled, prior to registering a user. This makes it possible for unauthenticated attackers t...
- CVSS:
- 5.3
- Affected:
- up to 2.1.2
- Fix:
- No patched version reported
- Disclosed:
- May 5, 2025
CVE-2025-3609 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database