Vulnerability Found in WordPress Security Plugin “Anti-Malware Security and Brute-Force Firewall,” Risk of Server Data Exposure
437/68 Friday, October 31, 2025 Security researchers have discovered a vulnerability in the popular WordPress plugin Anti-Malware Security and Brute-Force Firewall, which is installed on more than 100,000 websites worldwide. The flaw, tracked as CVE-2025-11705, stems from a missing capability check in the function GOTMLS_ajax_scan(), allowing users with subscriber-level access to invoke the function and […]
