CVE-2025-3776

CVSS 3.1 Score 8.3 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 94

Summary

CVE-2025-3776 is a Remote Code Execution vulnerability affecting the Verification SMS plugin for WordPress. The issue, present in all versions up to 1.5, stems from a lack of validation for the type of function that can be called through the 'targetvr_ajax_handler'. Consequently, unauthenticated attackers can exploit this vulnerability to execute any callable function on the site, including sensitive ones like phpinfo(). This poses a significant security risk and requires immediate attention and remediation. WordPress users are advised to update the plugin to the latest version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share