PatchSiren

RiceTheme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL RiceTheme CVE published 2026-01-08

CVE-2025-23993

A critical SQL injection vulnerability exists in the Felan Framework plugin, affecting versions up to and including 1.1.3. This issue allows attackers to inject malicious SQL code, potentially leading to unauthorized data access or modification. The vulnerability has a CVSS score of 9.3 and is considered critical. Defenders and security teams responsible for WordPress installations with the Felan Framewor [truncated]

CRITICAL RiceTheme CVE published 2026-01-08

CVE-2025-23504

A critical vulnerability was found in the Felan Framework, affecting versions up to and including 1.1.3. This issue allows for authentication bypass using an alternate path or channel, potentially leading to authentication abuse. The vulnerability has a CVSS score of 9.8 and is considered critical. Defenders and administrators should assess their exposure and prioritize updating to a secure version. The C [truncated]