ZeroHour

CVE-2025-10684

CVSS 3.1
4.3 medium
EPSS
<1%p2
Published
()
Modified
Description

The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .

Ecosystems
WordPress
Weakness
CWE-287, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.