CVE-2025-1063
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 25, 2025
Updated: Feb 28, 2025
CWE ID 200
Summary
CVE-2025-1063 is a vulnerability affecting the Classified Listing plugin for WordPress, versions up to 4.0.4. This issue allows unauthenticated attackers to extract sensitive information through the rtcl_taxonomy_settings_export function, exposing valuable data such as API keys and tokens. The vulnerability poses a significant risk to website security, as unauthorized access to these credentials can lead to unauthorized actions and data breaches. It is strongly recommended that users update to the latest version of the plugin to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Classified Listing Plugin
Affected Vendors
- WordPress