CVE-2025-1510
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 22, 2025
Updated: Mar 6, 2025
CWE ID 94
Summary
CVE-2025-1510: This vulnerability affects The Custom Post Type Date Archives plugin for WordPress. The issue lies in the plugin's failure to properly validate user inputs before running do_shortcode, enabling unauthenticated attackers to execute arbitrary shortcodes. Versions up to 2.7.1 are impacted, posing a significant risk for websites using this plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Custom Post Type Date Archives Plugin
Affected Vendors
- WordPress