PT-2025-36349 · WordPress · Adforest
Tonn
·
Published
2025-09-06
·
Updated
2025-10-02
·
CVE-2025-8359
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AdForest WordPress Theme versions prior to 6.1.0
Description
The AdForest theme for WordPress is susceptible to an authentication bypass, allowing unauthorized user access. The theme does not properly verify a user’s identity before authentication, potentially enabling attackers to log in as other users, including administrators, without a password.
Recommendations
Update AdForest to version 6.1.0 or later.
Disable the AdForest theme.
Restrict access to administrative accounts.
Monitor for suspicious login attempts.
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adforest