Ricetheme Felan Framework vulnerabilities
5 known vulnerabilities affecting ricetheme/felan_framework.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-10850P2CRITICALCVSS 9.8≤ 1.1.42025-10-16
CVE-2025-10850 [CRITICAL] CWE-798 CVE-2025-10850: The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to,
The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or_register' function. This makes it possible for unauthenticated attackers to log in as any existing user on the
nvd
CVE-2025-23504P2CRITICALCVSS 9.8≤ 1.1.32026-01-08
CVE-2025-23504 [CRITICAL] CWE-288 CVE-2025-23504: Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework
Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This issue affects Felan Framework: from n/a through <= 1.1.3.
nvd
CVE-2025-23993P2CRITICALCVSS 9.3≤ 1.1.32026-01-08
CVE-2025-23993 [CRITICAL] CWE-89 CVE-2025-23993: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allows SQL Injection.This issue affects Felan Framework: from n/a through <= 1.1.3.
nvd
CVE-2025-10849P4MEDIUMCVSS 5.3≤ 1.1.42025-10-16
CVE-2025-10849 [MEDIUM] CWE-862 CVE-2025-10849: The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a
The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_plugin_actions' function called via an AJAX action in versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to activate or deactivate arbitrary plugins.
nvd
CVE-2025-22741P4HIGHCVSS 7.1≥ n/a, ≤ 1.1.32026-05-27
CVE-2025-22741 [HIGH] CWE-79 CVE-2025-22741: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RiceTheme Felan Framework allows Reflected XSS.
This issue affects Felan Framework: from n/a through 1.1.3.
nvd