Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8420

Опубликовано: 06 авг. 2025
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version less than, or equal to, 2.5.2 via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called.

EPSS

Процентиль: 52%
0.00295
Низкий

8.1 High

CVSS3

Дефекты

CWE-95

Связанные уязвимости

CVSS3: 8.1
github
25 дней назад

The Request a Quote Form plugin for WordPress is vulnerable to Remote Code Execution in version less than, or equal to, 2.5.2 via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called.

EPSS

Процентиль: 52%
0.00295
Низкий

8.1 High

CVSS3

Дефекты

CWE-95