VYPR

Exertio Framework

by Scriptsbundle

CVEs (2)

  • CVE-2025-49402HigAug 28, 2025
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scriptsbundle Exertio Framework exertio-framework allows Blind SQL Injection.This issue affects Exertio Framework: from n/a through <= 1.3.3.

  • CVE-2024-13373HigMar 1, 2025
    risk 0.53cvss 8.1epss 0.00

    The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.1. This is due to the plugin not properly validating a user's identity prior to updating their password through the…