Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13648 | The PGS Core plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.8.0. This makes it possible for unauthenticated attackers to add, modify, or plugin options. |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 07 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 May 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The PGS Core plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.8.0. This makes it possible for unauthenticated attackers to add, modify, or plugin options. | |
| Title | PGS Core <= 5.8.0 - Missing Authorization via Multiple Functions | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:02:38.920Z
Reserved: 2025-01-29T18:41:52.271Z
Link: CVE-2025-0856
Updated: 2025-05-07T13:22:40.520Z
Status : Deferred
Published: 2025-05-06T23:15:51.260
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-0856
No data.
OpenCVE Enrichment
Updated: 2026-04-22T17:30:22Z
EUVD