CVE-2025-0316

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 8, 2025
CWE ID 288

Summary

CVE-2025-0316 is a vulnerability affecting the WP Directorybox Manager plugin for WordPress. In versions up to 2.5, an authentication bypass issue exists due to incorrect handling in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function. This flaw allows unauthenticated attackers to bypass authentication and log in as any existing user on the site, including administrators, if they have access to the targeted user's username. Successful exploitation of this vulnerability could result in unauthorized access, potentially leading to data theft or further system compromise. Users are advised to update to the latest version of the plugin as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share