First published: Fri Apr 04 2025(Updated: )
The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being used. This can be combined with CVE-2025-2797 to bypass the user approval process if an Administrator can be tricked into taking an action such as clicking a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Woffice CRM theme for WordPress | <=5.4.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2798 is classified as a high severity vulnerability due to the potential for unauthenticated attackers to gain Administrator access.
To fix CVE-2025-2798, update the Woffice CRM theme for WordPress to version 5.4.22 or later.
CVE-2025-2798 affects all versions of the Woffice CRM theme for WordPress up to and including 5.4.21.
CVE-2025-2798 allows unauthenticated users to register as Administrators due to misconfiguration of excluded roles.
CVE-2025-2798 was published on April 1, 2025.