WP Headless CMS Framework Protection Mechanism Bypass Vulnerability

Vulnerability

A protection mechanism bypass vulnerability has been identified in the WP Headless CMS Framework plugin for WordPress, affecting all versions through 1.15. The vulnerability arises because the plugin only verifies the presence of the Authorization header when deciding whether to bypass nonce protection. This oversight allows unauthenticated attackers to access restricted content.

Impact

Exploitation of this vulnerability could lead to unauthorized access to content that should be restricted.

Remediation

There is no known patch available for this vulnerability. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.

Added: Nov 13, 2025, 9:19 AM
Updated: Nov 13, 2025, 9:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
1.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.