CVE-2025-8420: CYBERLORD92 Employee Directory – Staff Directory And Listing
High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called
Affected products
- CYBERLORD92 Employee Directory – Staff Directory And Listing: up to and including 4.5.2
- Emarket-Design Campus Directory – Faculty, Staff & Student Directory Plugin For WordPress: up to and including 1.9.2
- Emarket-Design Customer Support Ticket System & Helpdesk Plugin For WordPress: up to and including 6.0.1
- Emarket-Design Event Rsvp And Simple Event Management Plugin: up to and including 4.2.1
- Emarket-Design Project Management, Bug And Issue Tracking Plugin – Software Issue Manager: up to and including 5.0.0
- Emarket-Design Request A Quote Form Plugin – Price Quote Request Management Made Easy: up to and including 2.5.2
- Emarket-Design Simple Contact Form Plugin For WordPress – Wp Easy Contact: up to and including 4.0.2
- Emarket-Design Video Gallery – YouTube Gallery & Responsive Video Playlist: up to and including 3.5.2
Published 2025-08-06. Last modified 2026-06-17.