CVE-2025-7955 – RingCentral Communications WordPress Authentication Bypass

CVE ID : CVE-2025-7955

Published : Aug. 28, 2025, 6:15 a.m. | 1 hour, 3 minutes ago

Description : The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Share the Post:

Related Posts