A vulnerability marked as critical has been reported in Felan Framework Plugin up to 1.1.4 on WordPress. This affects the function
fb_ajax_login_or_register
. This manipulation causes hard-coded credentials.
The identification of this vulnerability is CVE-2025-10850. It is possible to initiate the attack remotely. There is no exploit available.