> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2025-26936: WordPress Fresh Framework Plugin <= 1.70.0 is vulnerable to Remote Code Execution (RCE)
- URL: https://darkwebinformer.com/cve-2025-26936-wordpress-fresh-framework-plugin-1-70-0-is-vulnerable-to-remote-code-execution-rce/
- Published: 2025-03-10T16:44:31.000Z
- Updated: 2025-09-04T22:23:31.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities

🚨 Critical Security Vulnerability  
🆔 CVE-2025-26936  
💣 CVSS Score: 10  
📅 Published Date: 2025-03-10

⚠️ Details: Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Fresh Framework allows Code Injection. This issue affects Fresh Framework: from n/a through 1.70.0.

🛠 References:  
🔗 NIST: <https://nvd.nist.gov/vuln/detail/CVE-2025-26936>  
🔗 Patchstack: <https://patchstack.com/database/wordpress/plugin/fresh-framework/vulnerability/wordpress-fresh-framework-plugin-1-70-0-unauthenticated-remote-code-execution-rce-vulnerability?%5Fs%5Fid=cve>