All 4 CVE vulnerabilities found in Droip, with AI-generated Chinese analysis, references, and POCs.
Vendor: Themeum
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2025-5835 | Droip <= 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Many Actions CWE-862 | 8.8 | High | 2025-07-25 |
| CVE-2025-5831 | Droip < 2.5.2 - Authenticated (Subscriber+) Arbitrary File Upload CWE-434 | 8.8 | High | 2025-07-25 |
| CVE-2024-43955 | WordPress Droip plugin < 2.5.2 - Arbitrary File Deletion vulnerability CWE-22 | 10.0 | Critical | 2024-08-29 |
| CVE-2024-43954 | WordPress Droip plugin < 2.5.2 - Settings Change vulnerability CWE-862 | 6.3 | Medium | 2024-08-29 |
All 4 known CVE vulnerabilities affecting Droip with full Chinese analysis, references, and POCs where available.