CVE-2025-7955
CRITICALRingCentral Communications <1.6.8 - Auth Bypass
Title source: llmDescription
The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes.
Exploits (2)
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-7955
References (4)
Scores
CVSS v3
9.8
EPSS
0.0051
EPSS Percentile
66.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (1)
pbmacintyre/RingCentral Communications Plugin – FREE
1.5 - 1.6.8
Published
Aug 28, 2025
Tracked Since
Feb 18, 2026