Sensitive Information Exposure in g-FFL Cockpit Plugin for WordPress
CVE-2025-12721
5.3MEDIUM
What is CVE-2025-12721?
The g-FFL Cockpit plugin for WordPress is susceptible to Sensitive Information Exposure due to inadequate capability checks in the /server_status REST API endpoint. This vulnerability allows unauthenticated attackers to access potentially sensitive server information, posing a significant risk to the integrity and confidentiality of the server's configuration and data.
Affected Version(s)
g-FFL Cockpit * <= 1.7.1