Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23435 | The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for unauthenticated attackers to log in as other users, including administrators. |
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brave
Brave brave Wordpress Wordpress wordpress |
|
| Vendors & Products |
Brave
Brave brave Wordpress Wordpress wordpress |
Mon, 04 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 02 Aug 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for unauthenticated attackers to log in as other users, including administrators. | |
| Title | Brave Conversion Engine (PRO) <= 0.7.7 - Authentication Bypass to Administrator | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:56:35.243Z
Reserved: 2025-07-16T13:31:51.303Z
Link: CVE-2025-7710
Updated: 2025-08-04T13:23:06.768Z
Status : Deferred
Published: 2025-08-02T12:15:28.280
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-7710
No data.
OpenCVE Enrichment
Updated: 2026-04-21T19:30:06Z
EUVD