External risk intelligence

Felan Framework WordPress Plugin Hardcoded Password Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-10850

This vulnerability affects a WordPress plugin designed for public-facing freelance marketplace and job board websites. Because the plugin handles user authentication via web-accessible login functions and is intended for use on public websites, it is deployed as an internet-facing service by design.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in the Felan Framework plugin for WordPress that could allow unauthenticated attackers to log into user accounts. This issue stems from hardcoded passwords within the plugin's social login functions, potentially enabling unauthorized access if users haven't changed their default passwords after registering via Facebook or Google.

  • Unauthenticated access to user accounts.
  • Critical flaw in user login security.
  • Assess exposure to this WordPress plugin.

Attack Path

How an attacker could exploit the issue

An attacker can gain access to a WordPress site by exploiting a flaw in the Felan Framework plugin. This vulnerability allows unauthenticated users to log in as any existing user if that user registered with Facebook or Google and hasn't changed their password. The issue stems from hardcoded credentials within the plugin's authentication functions, enabling unauthorized access and potentially leading to full site compromise.

  • No user authentication is required.
  • Attackers trigger the vulnerability via login functions.
  • Risk includes unauthorized access and account takeover.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could log in as any user if that user registered with Facebook or Google and did not change their default password. This could allow unauthorized access to user accounts on WordPress sites using the Felan Framework plugin.

  • User account access.
  • Unauthenticated login via exposed functions.
  • Unauthorized access to user accounts.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Felan Framework WordPress plugin requires immediate attention from teams managing WordPress deployments and web application security. The primary action is to identify all instances of the plugin, determine their reachability and business criticality, and pinpoint the accountable application or platform owner. Remediation planning should be risk-based, potentially involving coordination with the plugin vendor if a fix is available or temporary mitigation strategies.

  • WordPress administrators and platform owners.
  • Verify plugin reachability and business criticality.
  • Plan remediation with vendor or implement mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Felan Framework WordPress plugin?

The Felan Framework is a component used within WordPress themes, specifically designed for creating freelance marketplaces and job board websites. It provides essential features to manage site functionality, including the integration of social login options like Facebook and Google to help users register and access their accounts more easily.

What does CWE-798 mean for CVE-2025-10850?

CWE-798 refers to the use of hardcoded credentials. In the context of this CVE, it means the plugin developers embedded a fixed, secret password directly into the source code for its social login functions. Because this password is static and cannot be changed by the user, it creates a significant security flaw that allows unauthorized parties to bypass authentication checks.

How do attackers trigger this vulnerability?

An attacker triggers this by interacting with the plugin's Facebook or Google login functions. The vulnerability does not allow access to every account on the system; it specifically targets users who registered using these social login methods and have not changed their account password afterward. If a user has updated their password since registration, the hardcoded credential will not grant access.

Is my site at risk if I use the Felan Framework?

According to Halo Surface Signal, this plugin is designed for public-facing marketplaces, meaning it is inherently internet-facing. Because it handles web-accessible authentication functions that are directly reachable by anyone on the internet, websites using this plugin are in a position where the vulnerability could be exercised by remote, unauthenticated actors.

What are the first steps to secure my installation?

You should immediately identify all WordPress sites in your environment running this plugin. Determine if the plugin is necessary for your current operations. If it is in use, review the developer's site for updates or patches that remove the hardcoded passwords. If no update is available, consider disabling the plugin's social login features or the plugin entirely until a secure version is released.

References