CVE-2025-14975Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-01-29); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-29: 2Mentions · 2026-01-31: 1Mentions · 2026-02-03: 1Technical Details · 2026-01-29: 2Technical Details · 2026-01-31: 1Technical Details · 2026-02-03: 101-2901-3102-03
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-292
Disclosure1General1
2026-01-311
Disclosure1
2026-02-031
Disclosure1
Full discourse4 posts
  • Nxploited@Nxploited
    Disclosure

    CVE-2025-14975 | ~90K affectedAutomated discovery & user enumeration, controlled reset‑key injection, session‑aware flow handling, privilege verification, modular exploitation, and concurrent processing with stealth.📩 Telegram: @KXploit #Vulnerability #CVE #Infosec https://t.co/7Nc8JQrhl5

    Post summary

    The message announces CVE‑2025‑14975, noting an estimated 90K affected systems and outlining technical exploitation vectors, but does not provide a PoC, exploit code, patch, or evidence of active attacks.

    10011255
    87 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-14975 The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the pas… https://www.cve.org/CVERecord?id=CVE-2025-14975

    Post summary

    The CVE-2025-14975 flaw allows unauthenticated password reset in the Custom Login Page Customizer plugin; no PoC, exploit code, or patch information is shared.

    00010261
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-14975 (CVSS:8.1, HIGH) is Awaiting Analysis. The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a..https://nvd.nist.gov/vuln/detail/CVE-2025-14975 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2025-14975, a high‑severity password reset flaw in the Custom Login Page Customizer WordPress plugin prior to version 2.5.4, with no PoC, exploit, or patch details provided yet.

    0000039
    171 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-14975 - High The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by know... https://www.thehackerwire.com/vulnerability/CVE-2025-14975/ https://t.co/79wYn6u5Ng

    Post summary

    High‑severity vulnerability in the Custom Login Page Customizer WordPress plugin allows unauthenticated users to reset any user password, exposing credentials to compromise.

    0000053
    113 followersView on X

Explore more