CVE-2025-2887
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 27, 2025
Updated: Mar 28, 2025
CWE ID 352
Summary
CVE-2025-2887 is a vulnerability affecting a specific client that fails to detect rollbacks during delegated target operations. This issue could result in the client fetching target contents from an incorrect source, leading to potential alterations. To mitigate this risk, users are advised to upgrade to version 0.20.0 or later of the affected software and ensure any forked or derivative codes are patched with the latest fixes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress