CVE-2025-11191

MEDIUM

RealPress <1.1.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.

References (1)

Core 1
Core References
Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/74f19ff2-d5c0-4bd4-83f2-688ea37022b1/

Scores

CVSS v3 5.3
EPSS 0.0027
EPSS Percentile 19.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
Unknown/RealPress < 1.1.0
Published Oct 31, 2025
Tracked Since Feb 18, 2026