Sploitus Multiple Vulnerabilities in WordPress Plugins Exposed
Article Content
- •CVE-2025-5947 allows unauthorized access via insecure AJAX endpoints in WordPress plugins.
- •CVE-2025-31651 enables bypassing security restrictions through crafted requests.
- •Both vulnerabilities have available PoC code, increasing the risk of exploitation.
Recent vulnerabilities in WordPress plugins have been identified, including CVE-2025-5947 affecting the Service Finder plugin, which allows unauthorized access through insecure AJAX endpoints. This vulnerability impacts numerous WordPress installations, particularly those using the Service Finder plugin for booking services. Additionally, CVE-2025-31651 has been reported, allowing attackers to bypass security restrictions in specific configurations through crafted requests. The scope of impact includes potentially thousands of WordPress sites, emphasizing the need for immediate attention from site administrators. Both vulnerabilities have proof-of-concept (PoC) code available, increasing the urgency for patching. The vulnerabilities were disclosed in September 2026, with CVE-2025-5947 being highlighted for its critical nature. Security researchers stress the importance of ethical practices when testing for these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2025-31651 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…