Author: Angelo Barbosa

CVE-2025-24538 | slaFFik BuddyPress Groups Extras Plugin up to 3.6.10 on WordPress cross-site request forgery

A vulnerability classified as problematic was found in slaFFik BuddyPress Groups Extras Plugin up to 3.6.10 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. This vulnerability is known as CVE-2025-24538. The attack can be launched remotely. There is no exploit...

Read More

CVE-2025-24540 | SeedProd Coming Soon Page, Under Construction & Maintenance Mode Plugin cross-site request forgery

A vulnerability classified as problematic has been found in SeedProd Coming Soon Page, Under Construction & Maintenance Mode Plugin up to 6.18.9 on WordPress. Affected is an unknown function. The manipulation leads to cross-site request forgery. This vulnerability is traded as CVE-2025-24540. It is possible to launch the attack remotely. There is no exploit...

Read More