← Volver a CVEs
CVE-2025-7955
CRITICAL9.8
Descripcion
The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado8/28/2025
Ultima modificacion8/29/2025
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-287
Referencias
https://plugins.trac.wordpress.org/browser/rccp-free/tags/1.6.8/ringcentral.php(security@wordfence.com)
https://plugins.trac.wordpress.org/changeset/3349361/(security@wordfence.com)
https://wordpress.org/plugins/rccp-free/#developers(security@wordfence.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.