CVE-2025-10849: Ricetheme Felan Framework

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_plugin_actions' function called via an AJAX action in versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to activate or deactivate arbitrary plugins.

Affected products

  • Ricetheme Felan Framework: up to and including 1.1.4

Published 2025-10-16. Last modified 2026-10-08.