The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to delete arbitrary products.
Metrics
Affected Vendors & Products
References
History
Sat, 06 Dec 2025 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to delete arbitrary products. | |
| Title | g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-12-06T05:49:25.295Z
Updated: 2025-12-06T05:49:25.295Z
Reserved: 2025-11-04T21:20:38.590Z
Link: CVE-2025-12720
No data.
Status : Received
Published: 2025-12-06T06:15:50.730
Modified: 2025-12-06T06:15:50.730
Link: CVE-2025-12720
No data.