CVE-2025-11191
MEDIUMCVSS 5.3/10EPSS 0.29%
Last modified
CVE-2025-11191 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-11191?
The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.
How severe is CVE-2025-11191?
CVE-2025-11191 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.29% probability of exploitation in the next 30 days.
How do I fix CVE-2025-11191?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-11186The Cookie Notice & Compliance for GDPR / CCPA plugin for Wo…6.4
- CVE-2025-11187Issue summary: PBMAC1 parameters in PKCS#12 files are missin…6.1
- CVE-2025-11188The Kiwire Captive Portal contains a blind SQL injection in …7.3
- CVE-2025-11189The Kiwire Captive Portal contains a reflected cross-site sc…7.3
- CVE-2025-1119The Appointment Booking Calendar — Simply Schedule Appointme…7.3
- CVE-2025-11190The Kiwire Captive Portal contains an open redirection issue…5.4
- CVE-2025-11192A vulnerability in Extreme Networks’ Fabric Engine (VOSS) be…8.6
- CVE-2025-11193A potential vulnerability was reported in some Lenovo Tablet…6.8
- CVE-2025-11195Rapid7 AppSpider Pro versions below 7.5.021 suffer from a pr…3.3
- CVE-2025-11196The External Login plugin for WordPress is vulnerable to sen…4.3
- CVE-2025-11197The Draft List plugin for WordPress is vulnerable to Stored …6.4
- CVE-2025-11198A Missing Authentication for Critical Function vulnerability…8.5
Are you affected by CVE-2025-11191?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
