CVE-2025-2840
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 29, 2025
Updated: Apr 1, 2025
CWE ID 284
Summary
CVE-2025-2840 is a vulnerability affecting the DAP to Autoresponders Email Syncing plugin for WordPress. This issue allows unauthenticated attackers to access sensitive information through the publicly exposed phpinfo.php script, which is contained within the plugin up to version 1.0. The exposure of such data can lead to potential security risks, making it essential for users to update or deactivate this plugin to mitigate the vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.