CVE-2025-1285
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 14, 2025
CWE ID 862
Summary
CVE-2025-1285 is a vulnerability affecting the Resido - Real Estate WordPress Theme for WordPress. The issue lies in the theme's lack of capability checks on the delete_api_key and save_api_key AJAX actions, which are available up to version 3.6. This vulnerability enables unauthenticated attackers to access internal services and update API key details, posing a threat to website security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.