← العودة للجدول
CVE-2019-25738
CVE-2019-25738 — WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vuln
📅 2026-06-04
🔴 Critical 🔥 No NVD Exploit Web CVSS 9.8

📋 الوصف الكامل

WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to hc_ajax_save_option to enable user registration and set the default role to administrator, enabling a

💻 الأنظمة المتأثرة

WordPress | PHP

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2019-25738

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2019-25738 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←