CVE-2025-11260
MEDIUMWP Headless CMS Framework <1.15 - Auth Bypass
Title source: llmDescription
The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.15. This is due to the plugin only checking for the existence of the Authorization header in a request when determining if the nonce protection should be bypassed. This makes it possible for unauthenticated attackers to access content they should not have access to.
Scores
CVSS v3
5.3
EPSS
0.0010
EPSS Percentile
26.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-693
Status
draft
Timeline
Published
Nov 13, 2025
Tracked Since
Feb 18, 2026