VYPR

Hybrid Composer

by WordPress

CVEs (1)

  • CVE-2019-25738CriJun 4, 2026
    risk 0.64cvss 9.8epss

    WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the…