CVE-2025-10850
CRITICALFelan Framework <1.1.4 - Auth Bypass
Title source: llmDescription
The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or_register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, if they registered with facebook or google social login and did not change their password.
Scores
CVSS v3
9.8
EPSS
0.0032
EPSS Percentile
54.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-798
Status
draft
Timeline
Published
Oct 16, 2025
Tracked Since
Feb 18, 2026