The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server.
Metrics
Affected Vendors & Products
References
History
Sat, 06 Dec 2025 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server. | |
| Title | g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-12-06T05:49:23.998Z
Updated: 2025-12-06T05:49:23.998Z
Reserved: 2025-11-04T21:24:44.906Z
Link: CVE-2025-12721
No data.
Status : Received
Published: 2025-12-06T06:15:50.900
Modified: 2025-12-06T06:15:50.900
Link: CVE-2025-12721
No data.