CVE-2025-12525
BaseFortify
Publication date: 2025-11-25
Last updated on: 2026-04-08
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpress | locker_content | 1.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Locker Content plugin for WordPress version 1.0.0. It allows unauthenticated attackers to access the 'lockerco_submit_post' AJAX endpoint and extract content from posts that are supposed to be protected by the plugin, leading to sensitive information exposure.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of protected post content, meaning sensitive or confidential information that was intended to be secured by the plugin can be accessed by anyone without authentication. This can result in data leaks and potential privacy breaches.