Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2025-07-22
CVE-2025-6721 - Vchasno Kasa Plugin
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mrkv_vchasno_kasa_wc_do_metabox_action() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to generate invoices for arbitrary orders.
PLUGIN
Vchasno Kasa
CVE-2025-6721
Risk Score
Threat Entry
Updated 2025-07-22
CVE-2025-6720 - Vchasno Kasa Plugin
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to clear log files.
PLUGIN
Vchasno Kasa
CVE-2025-6720
Risk Score
