Skip to content

CVE-2025-11833

CVE

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 4, 2025
Last Seen
January 20, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A security vulnerability in the Post SMTP plugin, used in over 400,000 WordPress installations, has been discovered that enables unauthenticated attackers to take control of administrator accounts and entire WordPress sites. The flaw was reported to Wordfence on October 11, and attacks exploiting th...

The Pennsylvania Attorney General's Office confirmed that a ransomware attack in August 2025, attributed to the INC ransomware group, resulted in the theft of personal information, including names, Social Security numbers, and medical details. Although the number of affected individuals has not been...

Three cybersecurity professionals have been indicted for allegedly conducting ransomware attacks using the BlackCat (ALPHV) strain against five U.S. companies between May and November 2023. The accused, Ryan Clifford Goldberg and Kevin Tyler Martin, were previously employed by cybersecurity firms an...

A critical security vulnerability has been identified in the Advanced Custom Fields: Extended plugin for WordPress, affecting up to 100,000 websites. The flaw allows unauthenticated attackers to gain administrative permissions, with a severity rating of 9.8 assigned to the vulnerability, tracked as...

Public Exploits

Checking GitHub for proof-of-concept code…