🚨 Critical Security Vulnerability
🆔 CVE-2025-26936
💣 CVSS Score: 10
📅 Published Date: 2025-03-10
⚠️ Details: Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Fresh Framework allows Code Injection. This issue affects Fresh Framework: from n/a through 1.70.0.
🛠 References:
🔗 NIST: https://nvd.nist.gov/vuln/detail/CVE-2025-26936
🔗 Patchstack: https://patchstack.com/database/wordpress/plugin/fresh-framework/vulnerability/wordpress-fresh-framework-plugin-1-70-0-unauthenticated-remote-code-execution-rce-vulnerability?_s_id=cve