Beveiligingsadvies

CVE-2025-2798

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-04-04 13:44:36
Laatst bijgewerkt 2026-04-08 16:59:32
Toegewezen door Wordfence
CVSS-score 9.8
Status PUBLISHED

Beschrijving

The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being used. This can be combined with CVE-2025-2797 to bypass the user approval process if an Administrator can be tricked into taking an action such as clicking a link.