TGViewer
WebHostMost | The Web Hosting Community WebHostMost | The Web Hosting Community @webhostmost · 449 subscribers
Post #91 142
📰 INDUSTRY NEWS

🚨 WordPress Plugin Branda: Admin Takeover Without Authentication

CVE-2025-14998 just dropped. CVSS score: 9.8 (CRITICAL)

The Branda white-label plugin (10,000+ active installs) allows anyone to reset admin passwords without authentication.

Attack flow:
→ Send crafted request
→ Change admin password
→ Log in as admin
→ Full site compromise

Affected: All versions ≤ 3.4.24
Patched: Version 3.4.25 (January 2, 2026)

Who uses Branda?
→ WordPress agencies
→ White-label developers
→ Multi-site managers

One compromised client site = entry point to entire portfolio.

Update immediately. Check user accounts for suspicious additions. Regenerate WordPress salts.

This is the 4th critical (9.8+) WordPress plugin vulnerability in January alone.

Pattern is clear.

Stay tuned! 🤓

#WordPress #Security #CVE #Branda #WebHostMost
  • 😱 5
  • 🫡 4
  • 🙉 4
More from @webhostmost
  1. May 4, 2026📰 INDUSTRY NEWS AI agents can now buy domains. No human required. On April 15, Cloudflare…
  2. Apr 30, 2026💡 USE CASE Hosting is not just WordPress sites. FragalyseQt is an open-source tool for DN…
  3. Apr 10, 2026🚨 VULNERABILITY UPDATE 🛡 Hackers exploiting Acrobat Reader zero-day flaw since December…
  4. Apr 1, 2026📣 WEBHOSTMOST PROMO Let’s get straight to the data: This is NOT an April Fools joke. 📉 O…
  5. Mar 26, 2026📰 INDUSTRY NEWS The era of the $2.99 shared hosting plan is officially fading. 📉 The 202…
  6. Mar 20, 2026📰 INDUSTRY NEWS Linux MGLRU: +30% Database Performance Boost 🚀 New optimizations for Mul…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →