CVE-2025-14998Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-03); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-17: 1Mentions · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-24: 1Active Exploitation · 2026-02-03: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-17: 1Technical Details · 2026-08-24: 102-0302-1708-24
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-031
Active Exploitation1
2026-02-171
Disclosure1
2026-08-241
Disclosure1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-14998 - critical 🚨 Branda WordPress plugin - Privilege Escalation > Branda WordPress plugin <= 3.4.24 contains a privilege escalation caused by improper ... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-14998 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE‑2025‑14998 is a critical privilege‑escalation flaw disclosed for Branda WordPress plugin versions up to 3.4.24, with a link to ProjectDiscovery’s library for details, but no exploit code, active exploitation, patch, or false‑positive claim is provided.

    00032320
    1.3K followersView on X
  • y1 uda@abyo software@y1uda
    Disclosure

    CVE-2025-14998: Brandaのパスワードリセットによるアカウント乗っ取り [CVSS 9.8 Critical] | Nyambush セキュリティブログ https://nyambush.app/blog/wp-branda-account-takeover #Nyambush #WordPress #WPSec #セキュリティ

    Post summary

    The Nyambush blog announces a critical CVE-2025-14998 affecting the Branda plugin, detailing a password reset flaw that permits account takeover and providing a CVSS 9.8 rating.

    0000081
    175 followersView on X
  • Valentin Scerbacov@notVallium
    Active Exploitation

    WordPress Branda plugin: CVE-2025-14998, CVSS 9.8 Anyone can reset your admin password. No authentication required. Attack flow looks like: 1. Send crafted request 2. Change admin password 3. Log in as admin 4. Full site control 10,000+ sites affected. Update to 3.4.25 immediately. This is the 4th critical WordPress plugin vuln last month. http://t.me/webhostmost #WordPress #CyberSecurity #CVE

    Post summary

    CVE‑2025‑14998 allows unauthenticated password reset in WordPress Branda plugin, affecting over 10,000 sites; users are urged to upgrade to version 3.4.25 immediately.

    0000059
    29 followersView on X

Explore more