The g-FFL Cockpit plugin for WordPress is vulnerable to...
Moderate severity
Unreviewed
Published
Dec 6, 2025
to the GitHub Advisory Database
•
Updated Dec 6, 2025
Description
Published by the National Vulnerability Database
Dec 6, 2025
Published to the GitHub Advisory Database
Dec 6, 2025
Last updated
Dec 6, 2025
The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the handle_enqueue_only() function in all versions up to, and including, 1.7.1. This makes it possible for unauthenticated attackers to delete arbitrary products.
References