CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-14044: Visitor Logic Lite 0 through 1.0.3

CVE-2025-14044. CVSS 3.1 base score 8.1 (HIGH, Vendor/CNA). EPSS 0.00544 (percentile 0.43819), scored 2026-10-06.

Affected technology

Visitor Logic Lite · 0 through 1.0.3
rodgerholl

Component: Not specified by the source
Function: passing

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source says if a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code granted they can access the WordPress site. Vendor/CNA’s CVSS 3.1 assessment (base score 8.1/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-502
CCR priority
32.5 /100 (P4)
CVSS 3.1
8.1 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
EPSS
0.00544 · percentile 0.43819 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-14044.html