Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-12-08

CVE-2025-12721 - G Ffl Cockpit Plugin

The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server.

PLUGIN G Ffl Cockpit

CVE-2025-12721

MEDIUM CVSS 5.3 2025-12-06
Threat Entry Updated 2025-12-08

CVE-2025-12720 - G Ffl Cockpit Plugin

The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to delete arbitrary products.

PLUGIN G Ffl Cockpit

CVE-2025-12720

MEDIUM CVSS 5.3 2025-12-06
Scroll to top