Reales WP STPT Privilege Escalation Vulnerability via Account Takeover

Vulnerability

A privilege escalation vulnerability allowing account takeover has been identified in the Reales WP STPT plugin for WordPress, affecting all versions through 2.1.2. The issue arises because the plugin fails to properly validate a user's identity before allowing updates to account details such as passwords and email addresses. This flaw enables authenticated attackers with subscriber-level access or higher to change the passwords and email addresses of any user, including administrators, thereby gaining unauthorized access to their accounts. Furthermore, this vulnerability can be exploited in conjunction with CVE-2025-3609 to achieve remote code execution as an initially unauthenticated user without an account.

Impact

Exploitation of this vulnerability allows for unauthorized password and email address changes, leading to account takeover. If combined with CVE-2025-3609, it could result in remote code execution.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.