CVE-2025-7710: Brave Conversion Engine (PRO) <= 0.7.7 - Authentication Bypass to Administrator
The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for unauthenticated attackers to log in as other users, including administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7710?
CVE-2025-7710 has a high severity rating due to its potential for authentication bypass.
How do I fix CVE-2025-7710?
To fix CVE-2025-7710, update the Brave Conversion Engine (PRO) plugin to version 0.7.8 or higher.
Who is affected by CVE-2025-7710?
CVE-2025-7710 affects users of the Brave Conversion Engine (PRO) plugin for WordPress in versions up to 0.7.7.
What type of vulnerability is CVE-2025-7710?
CVE-2025-7710 is classified as an Authentication Bypass vulnerability.
Can CVE-2025-7710 allow unauthorized access?
Yes, CVE-2025-7710 can potentially allow unauthorized access due to improper identity restrictions during authentication.