Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-12721. PoCs published by d0n601.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2025-12721, an unauthenticated information exposure vulnerability in the g-FFL Cockpit WordPress plugin. It includes code snippets, endpoint details, and a reproduction method, demonstrating a clear understanding of the vulnerability's root cause.
Description
The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2025-12721, an unauthenticated information exposure vulnerability in the g-FFL Cockpit WordPress plugin. It includes code snippets, endpoint details, and a reproduction method, demonstrating a clear understanding of the vulnerability's root cause.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N