NVD disclosure day

Published threat advisories for October 3, 2025

CVE advisoryCRITICAL

CVE-2025-59943

phpMyFAQ Account Ambiguity Due to Duplicate Email Registration.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

phpMyFAQ, an open-source FAQ web application, has a vulnerability allowing multiple accounts to share an email address. This can cause account confusion and potentially lead to unauthorized access or control if email is used for password resets or administrative actions. It is important to verify if your phpMyFAQ insta

CVE advisoryCRITICAL

CVE-2025-9286

Appy Pie Connect for WooCommerce Privilege Escalation.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in the Appy Pie Connect for WooCommerce WordPress plugin allows unauthenticated attackers to reset any user's password, potentially granting administrative access. This vulnerability is reachable via a public REST API. The primary concern is confirming if this plugin is in use and if its API is exposed.

CVE advisoryCRITICAL

CVE-2025-9209

RestroPress Authentication Bypass via User Data Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An authentication bypass vulnerability exists in a WordPress online ordering plugin, enabling unauthenticated attackers to forge JWT tokens and impersonate users, including administrators, by exploiting exposed API data. This could lead to unauthorized access to user accounts and administrative functions. Confirmation

CVE advisoryCRITICAL

CVE-2025-10726

WPRecovery SQL Injection and Arbitrary File Deletion Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The WPRecovery WordPress plugin has a SQL injection vulnerability that could allow unauthenticated attackers to extract sensitive database information or delete arbitrary files on the server. This is due to insufficient escaping of the 'data[id]' parameter, enabling the injection of malicious SQL queries. This could le

CVE advisoryCRITICAL

CVE-2025-6388

Spirit Framework WordPress Plugin Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The Spirit Framework plugin for WordPress has an authentication bypass vulnerability, allowing unauthenticated attackers to log in as any user if they know the username, potentially gaining administrative access. This could lead to unauthorized control of WordPress sites, which are often internet-facing.