VYPR

Cs Framework

by WordPress

CVEs (2)

  • CVE-2024-12035HigMar 7, 2025
    risk 0.58cvss 8.8epss 0.01

    The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Subscriber-level…

  • CVE-2024-12036HigMar 7, 2025
    risk 0.49cvss 7.5epss 0.00

    The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of…