Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemesGrove WP SmartPay allows Authentication Abuse. This issue affects WP SmartPay: from n/a through 2.7.13.
We have discovered 41 live websites that are affected by CVE-2025-25171.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 41 live websites (100% of Smartpay install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 28 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 21 websites |
| .org | 9 websites |
| .net | 2 websites |
| .nl | 2 websites |
| .de | 1 websites |
| .se | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ************.com | *,***,*** | ||
| ************.**.za | *,***,*** | ||
| ******************.org | **,***,*** | ||
| ***********.com | **,***,*** | ||
| *******.org | **,***,*** | ||
| ***********.com | **,***,*** | ||
| *****.org | **,***,*** | ||
| **************.nl | **,***,*** | ||
| **************.com | **,***,*** | ||
| **********.de | **,***,*** |
FAQ