Description
The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other users, including administrators, without access to a password.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
* (semver)
Timeline
2025-07-30: | Vendor Notified |
2025-09-05: | Disclosed |
Credits
Tonn
References
www.wordfence.com/...-1113-484b-80ed-09515982c585?source=cve
themeforest.net/...orest-classified-wordpress-theme/19481695