CVE-2025-49895: Ithemes Serverbuddy By Pluginbuddy.com

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This issue affects ServerBuddy by PluginBuddy.Com: from n/a through 1.0.5.

Affected products

  • Ithemes Serverbuddy By Pluginbuddy.com: up to and including 1.0.5

Published 2025-08-16. Last modified 2026-06-17.