AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-25002

HIGH · CVSS 7.5 EPSS 1.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-05-02 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects WordPress. Exploitation may require the attacker to be authenticated.

CVE
CVE-2021-25002
Severity
HIGH
CVSS
7.5
EPSS
1.50%
WordPress

Original NVD Description

The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL