High 7.1 Unfixed Closed
2025-01-27≤ 1.4.5
CVE-2025-23756
CVE-2025-23756
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress LawPress – Law Firm Website Management Plugin <= 1.4.5 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress LawPress – Law Firm Website Management plugin <= 1.4.4 - Sensitive Information Disclosure vulnerability
WordPress LawPress – Law Firm Website Management plugin <= 1.4.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability