CVE-2025-23504

9.8

RiceTheme · Felan Framework

The RiceTheme Felan Framework plugin for WordPress is vulnerable to an authentication bypass, allowing unauthenticated attackers to gain unauthorized access to the application.

Executive summary

An unauthenticated authentication bypass vulnerability in the RiceTheme Felan Framework plugin poses a critical risk of full account takeover.

Vulnerability

This vulnerability is an Authentication Bypass Using an Alternate Path or Channel (CWE-288). It allows an unauthenticated attacker to bypass security controls and potentially perform unauthorized administrative actions.

Business impact

Successful exploitation allows an attacker to gain unauthorized access to the affected site, leading to potential full account takeover. Given the CVSS score of 9.8, the business impact is severe, including total compromise of data confidentiality, integrity, and system availability.

Remediation

Immediate Action: As no patched version is currently available, administrators must immediately deactivate and remove the Felan Framework plugin from the environment until a fix is released.

Proactive Monitoring: Review web server and WordPress authentication logs for unusual login patterns, unexpected administrative account creation, or anomalous API access.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious traffic patterns or unauthorized attempts to access framework-specific endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The absence of a vendor-provided patch necessitates immediate removal of the plugin to prevent potential exploitation. Security teams should prioritize the identification of any instances of the Felan Framework within their WordPress ecosystem and ensure the software is fully deactivated immediately.