CVE-2025-2798
Last modified
CVE-2025-2798 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being used. This can be combined with CVE-2025-2797 to bypass the user approval process if an Administrator can be tricked into taking an action such as clicking a link.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xtendify | Woffice | < 5.4.22 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-2798?
How severe is CVE-2025-2798?
How do I fix CVE-2025-2798?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27953An issue in Clinical Collaboration Platform 12.2.1.5 allows …6.5
- CVE-2025-27954An issue in Clinical Collaboration Platform 12.2.1.5 allows …6.5
- CVE-2025-27955Clinical Collaboration Platform 12.2.1.5 has a weak logout s…6.5
- CVE-2025-27956Directory Traversal vulnerability in WebLaudos 24.2 (04) all…7.5
- CVE-2025-2796On affected platforms with hardware IPSec support running Ar…5.3
- CVE-2025-2797The Woffice Core plugin for WordPress is vulnerable to Cross…5.4
- CVE-2025-27980cashbook v4.0.3 has an arbitrary file read vulnerability in …6.5
- CVE-2025-2799The WP Event Manager – Events Calendar, Registrations, Sell …4.8
- CVE-2025-27997An issue in Blizzard Battle.net v2.40.0.15267 allows attacke…8.4
- CVE-2025-27998An issue in Valvesoftware Steam Client Steam Client 17380262…8.4
- CVE-2025-2800The WP Event Manager – Events Calendar, Registrations, Sell …6.1
- CVE-2025-28009A SQL Injection vulnerability exists in the `u` parameter of…9.8
Are you affected by CVE-2025-2798?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
