5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description
The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.
Basic Information
ID
CVE-2025-11191
Source
WPScan
Published
Oct 31, 2025 at 06:00
Modified
Oct 31, 2025 at 14:03
Affected Product
Vendor
Unknown
Product
RealPress
Affected Versions
Unknown RealPress 0