CVE-2025-12721: Garidium G-Ffl Cockpit

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the /server_status REST API endpoint due to a lack of capability checks. This makes it possible for unauthenticated attackers to extract information about the server.

Affected products

  • Garidium G-Ffl Cockpit: up to and including 1.7.1

Published 2025-12-06. Last modified 2026-06-17.