The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Fri, 31 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 31 Oct 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site. | |
| Title | RealPress < 1.1.0 - Unauthenticated Content Creation/Email Sending via REST | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-10-31T06:00:03.402Z
Updated: 2025-10-31T14:03:01.749Z
Reserved: 2025-09-30T12:38:44.699Z
Link: CVE-2025-11191
Updated: 2025-10-31T14:02:21.621Z
Status : Awaiting Analysis
Published: 2025-10-31T06:15:32.917
Modified: 2025-11-04T15:41:56.843
Link: CVE-2025-11191
No data.