CVE-2025-2883
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-2883 is a vulnerability affecting the Accept SagePay Payments plugin for WordPress. Versions up to 2.0 of this plugin expose sensitive information through the publicly accessible phpinfo.php script. This issue allows unauthenticated attackers to view potentially confidential data contained within the file. The vulnerability poses a significant risk as sensitive information exposure can lead to data breaches and unauthorized access to systems. WordPress users running affected versions of the plugin are urged to update to the latest version immediately to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.