CVE-2025-3255
CVSS 3.1 Score 8.5 of 10 (high)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 89
Summary
CVE-2025-3255 is a newly identified vulnerability affecting the xujiangfei admintwo version 1.0 software. This issue poses a significant security risk as it allows for improper access controls when manipulating the argument ID in the /user/home functionality. Consequently, an attacker can exploit this vulnerability remotely. Regrettably, the exploit for this flaw has been made public, increasing the likelihood of successful attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress