CVE-2025-67944 is a critical code injection vulnerability affecting Nelio Software's Nelio AB Testing plugin, specifically versions up to and including 8.1.8. This flaw allows for improper control of code generation, enabling attackers to inject malicious code. With a CVSS score of 9.1 (CRITICAL), it presents a low-complexity network attack vector requiring only low privileges, potentially leading to high confidentiality, low integrity, and low availability impacts. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 8.1.8CPE match | cpe:2.3:a:neliosoftware:nelio_ab_testing:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.