CVE-2025-1510

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 22, 2025
Updated: Mar 6, 2025
CWE ID 94

Summary

CVE-2025-1510: This vulnerability affects The Custom Post Type Date Archives plugin for WordPress. The issue lies in the plugin's failure to properly validate user inputs before running do_shortcode, enabling unauthenticated attackers to execute arbitrary shortcodes. Versions up to 2.7.1 are impacted, posing a significant risk for websites using this plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Custom Post Type Date Archives Plugin

Affected Vendors

  • WordPress