CVE 5.3 MEDIUM

RealPress < 1.1.0 - Unauthenticated Content Creation/Email Sending via REST_CVE-2025-11191

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.

Basic Information

ID CVE-2025-11191
Source WPScan
Published Oct 31, 2025 at 06:00
Modified Oct 31, 2025 at 14:03

Affected Product

Vendor Unknown
Product RealPress
Affected Versions Unknown RealPress 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.