CVE-2025-49895
BaseFortify
Publication date: 2025-08-16
Last updated on: 2026-04-28
Assigner: Patchstack
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pluginbuddy | serverbuddy | 1.0.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
| CWE-352 | The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the iThemes ServerBuddy plugin by PluginBuddy.Com. It allows an attacker to perform Object Injection, which can lead to unauthorized actions being executed on behalf of a user without their consent.
How can this vulnerability impact me? :
The vulnerability can have a severe impact, including unauthorized access and control over the affected system. It can lead to complete compromise of confidentiality, integrity, and availability of the system, as indicated by the high CVSS score (8.8) with high impact on confidentiality, integrity, and availability.