CVE-2025-2882
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 8, 2025
CWE ID 200
Summary
CVE-2025-2882 is a vulnerability affecting the GreenPay(tm) plugin for WordPress. Versions 3.0.0 to 3.0.9 of the plugin contain a sensitive information exposure issue. This vulnerability allows unauthenticated attackers to access the phpinfo.php script publicly, enabling them to view potentially sensitive information contained within the file. This exposure can lead to security risks, making it essential for users to update their plugins to the latest version or implement other mitigation strategies.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.