Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Visual Text Editor allows Remote Code Inclusion. This issue affects Visual Text Editor: from n/a through 1.2.1.
History

Wed, 26 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Visual Text Editor allows Remote Code Inclusion. This issue affects Visual Text Editor: from n/a through 1.2.1.
Title WordPress Visual Text Editor plugin <= 1.2.1 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2025-03-26T14:24:23.579Z

Updated: 2025-03-26T14:59:05.138Z

Reserved: 2025-03-11T08:09:09.176Z

Link: CVE-2025-28893

cve-icon Vulnrichment

Updated: 2025-03-26T14:59:01.227Z

cve-icon NVD

Status : Received

Published: 2025-03-26T15:16:15.873

Modified: 2025-03-26T15:16:15.873

Link: CVE-2025-28893

cve-icon Redhat

No data.