CVE-2025-12721 - g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure
CVE ID : CVE-2025-12721
Published : Dec. 6, 2025, 5:49 a.m. | 25 minutes ago
Description : The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Dec. 6, 2025, 5:49 a.m. | 25 minutes ago
Description : The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...