Логотип exploitDog
bind:CVE-2025-0749
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-0749

Количество 2

Количество 2

nvd логотип

CVE-2025-0749

11 месяцев назад

The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first verified user.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-vv6r-gfm2-qf53

11 месяцев назад

The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first verified user.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-0749

The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first verified user.

CVSS3: 8.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-vv6r-gfm2-qf53

The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes it possible for unauthenticated attackers to log in to the first verified user.

CVSS3: 8.1
0%
Низкий
11 месяцев назад

Уязвимостей на страницу