CVE-2025-27294
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2025-27294 is a newly identified vulnerability affecting WP-Asambleas, a popular WordPress plugin. This issue involves missing authorization controls, making it possible for unauthorized users to exploit incorrectly configured access levels. The vulnerability puts versions of WP-Asambleas from n/a to 2.85.0 at risk, potentially leading to significant security implications for WordPress websites using this plugin. The exact nature of the exploit is yet to be determined, but it underscores the importance of maintaining proper access control and keeping software up to date to protect against such threats.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.