The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. This makes it possible for unauthenticated attackers to extract sensitive data including authentication credentials, which can be used to log in as other users as long as they have used the plugin's custom authentication feature before. This may include administrators, which makes a complete site takeover possible.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ce21
Ce21 ce21-suite Wordpress Wordpress wordpress |
|
| Vendors & Products |
Ce21
Ce21 ce21-suite Wordpress Wordpress wordpress |
Tue, 04 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. This makes it possible for unauthenticated attackers to extract sensitive data including authentication credentials, which can be used to log in as other users as long as they have used the plugin's custom authentication feature before. This may include administrators, which makes a complete site takeover possible. | |
| Title | CE21 Suite <= 2.3.1 - Unauthenticated Sensitive Information Exposure to Privilege Escalation | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-04T03:26:46.726Z
Updated: 2025-11-04T18:48:23.226Z
Reserved: 2025-09-25T20:57:59.568Z
Link: CVE-2025-11008
Updated: 2025-11-04T18:48:20.734Z
Status : Awaiting Analysis
Published: 2025-11-04T04:15:37.113
Modified: 2025-11-04T15:40:45.533
Link: CVE-2025-11008
No data.