CVE-2025-2798

The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being used. This can be combined with CVE-2025-2797 to bypass the user approval process if an Administrator can be tricked into taking an action such as clicking a link.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:xtendify:woffice:*:*:*:*:*:wordpress:*:*

History

08 Aug 2025, 20:03

Type Values Removed Values Added
References () https://hub.woffice.io/woffice/changelog#april-1st-2025-version-5422 - () https://hub.woffice.io/woffice/changelog#april-1st-2025-version-5422 - Release Notes
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/6dd6169b-bc94-4642-8975-2e96bc01576f?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/6dd6169b-bc94-4642-8975-2e96bc01576f?source=cve - Third Party Advisory
CPE cpe:2.3:a:xtendify:woffice:*:*:*:*:*:wordpress:*:*
First Time Xtendify
Xtendify woffice

09 Jun 2025, 20:15

Type Values Removed Values Added
References
  • {'url': 'http://localhost/wp-content/themes/woffice/inc/classes/Woffice_Register.php#L405', 'name': 'http://localhost/wp-content/themes/woffice/inc/classes/Woffice_Register.php#L405', 'tags': [], 'refsource': ''}
CWE CWE-269
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : unknown

04 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-04 14:15

Updated : 2025-08-08 20:03


NVD link : CVE-2025-2798

Mitre link : CVE-2025-2798


JSON object : View

Products Affected

xtendify

  • woffice
CWE

No CWE.