9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. This makes it possible for unauthenticated attackers to extract sensitive data including authentication credentials, which can be used to log in as other users as long as they have used the plugin's custom authentication feature before. This may include administrators, which makes a complete site takeover possible.
AI Analysis
Unauthenticated Sensitive Information Exposure to Privilege Escalation via log file in CE21 Suite plugin for WordPress
Basic Information
ID
CVE-2025-11008
Source
Wordfence
Published
Nov 4, 2025 at 03:26
Affected Product
Vendor
ce21com
Product
CE21 Suite
Version
*
Affected Versions
ce21com CE21 Suite *
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
ce21com
Product
CE21 Suite
Version
2.3.1