CVE-2025-26961
CVE-2025-26961
Título es
CVE-2025-26961
Sáb, 15/03/2025 – 22:15
Tipo
CWE-862
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-26961
Descripción en
Missing Authorization vulnerability in NotFound Fresh Framework allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fresh Framework: from n/a through 1.70.0.
15/03/2025
15/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Gravedad 3.1 (CVSS 3.1 Base Score)
8.60
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
HIGH
Referencias
https://patchstack.com/database/wordpress/plugin/fresh-framework/vulnerability/wordpress-fresh-framework-plugin-1-70-0-unauthenticated-broken-access-control-vulnerability?_s_id=cve
Enviar en el boletín
Off
