Authentication Bypass in Brave Conversion Engine Plugin for WordPress
CVE-2025-7710
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 August 2025
What is CVE-2025-7710?
The Brave Conversion Engine (PRO) plugin for WordPress suffers from an Authentication Bypass vulnerability across all versions up to 0.7.7. This flaw arises from the plugin's failure to adequately restrict user identities during authentication processes with Facebook. As a result, unauthorized attackers can exploit this weakness to gain access to user accounts, potentially compromising sensitive information and system integrity, including administrative accounts.
Affected Version(s)
Brave Conversion Engine (PRO) * <= 0.7.7