Authentication Bypass Vulnerability in Spirit Framework Plugin for WordPress
CVE-2025-6388
9.8CRITICAL
What is CVE-2025-6388?
The Spirit Framework plugin for WordPress is flawed due to its custom_actions() function, which fails to properly validate user identities before allowing authentication. This vulnerability allows unauthenticated attackers to gain access to the site as any user, including those with administrative privileges, provided they know the administrator’s username. It poses a significant risk as it enables malicious actors to exploit this weakness and potentially manipulate the website.
Affected Version(s)
Spirit Framework * <= 1.2.14