VYPR

Spirit Framework

by WordPress

CVEs (3)

  • CVE-2025-6388CriOct 3, 2025
    risk 0.64cvss 9.8epss 0.01

    The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.2.14. This is due to the custom_actions() function not properly validating a user's identity prior to authenticating them to the site. This makes it possible…

  • CVE-2024-54263HigFeb 2, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allows PHP Local File Inclusion.This issue affects Spirit Framework: from n/a through 1.2.13.

  • CVE-2025-10269HigSep 12, 2025
    risk 0.49cvss 7.5epss 0.01

    The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server,…