CVE-2025-25171

WordPress WP SmartPay plugin <= 2.7.13 - Account Takeover vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemesGrove WP SmartPay allows Authentication Abuse. This issue affects WP SmartPay: from n/a through 2.7.13.


We have discovered 41 live websites that are affected by CVE-2025-25171.

Run a Free Instant Scan




Affected Software

Product  Smartpay
Category Wordpress Plugins
Vulnerable Domains41 live websites (100% of Smartpay install base)
Vulnerable Versions
  • from 0 through 2.7.13
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Jun 27, 2025
  • Updated - Jun 27, 2025

Credits

  • Le Ngoc Anh (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-25171
United States28 websites



Canada2 websites
Germany2 websites
Netherlands2 websites
Australia1 websites
Estonia1 websites
Spain1 websites
France1 websites
Ireland1 websites
Sweden1 websites

Website Distribution by TLD

Number of websites using CVE-2025-25171
.com21 websites
.org9 websites
.net2 websites
.nl2 websites
.de1 websites
.se1 websites

Websites affected by CVE-2025-25171

Top websites that are affected by CVE-2025-25171. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States*,***,***
************.**.za South Africa*,***,***
******************.org France**,***,***
***********.com United States**,***,***
*******.org United States**,***,***
***********.com Estonia**,***,***
*****.org United States**,***,***
**************.nl Netherlands**,***,***
**************.com United States**,***,***
**********.de Germany**,***,***
See full domain list

FAQ

CVE-2025-25171 is Authentication Bypass Using an Alternate Path or Channel in Smartpay
A total of 41 websites have been identified as vulnerable to CVE-2025-25171, based on global website indexing conducted by WebTechSurvey.
The Smartpay is affected by the CVE-2025-25171 vulnerability.
Smartpay versions up to and including 2.7.13 are vulnerable to CVE-2025-25171.