Description
The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_plugin_actions' function called via an AJAX action in versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to activate or deactivate arbitrary plugins.
Problem types
Product status
*
Timeline
2025-09-22: | Discovered |
2025-10-15: | Disclosed |
Credits
István Márton
References
www.wordfence.com/...-132a-4d8b-bfcc-afd5c6ed9947?source=cve
themeforest.net/...ce-and-job-board-wordpress-theme/53612955