Brute Force Vulnerability in Session Management for WordPress
CVE-2025-48461

5MEDIUM

Key Information:

Vendor

Advantech

Vendor
CVE Published:
24 June 2025

What is CVE-2025-48461?

This vulnerability allows unauthenticated users to exploit predictable session cookies within the WordPress platform. As a result, attackers can perform brute force guessing attacks that may lead to unauthorized account takeover, enabling them to gain root, admin, or user privileges. This flaw poses a serious risk as it could allow malicious actors to reset passwords and compromise sensitive information.

Affected Version(s)

Advantech Wireless Sensing and Equipment (WISE) A2.01 B00

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joel Chang Zhi Kai
.
CVE-2025-48461 : Brute Force Vulnerability in Session Management for WordPress