CVE-2026-25394 | sparklewpthemes Fitness FSE Plugin up to 1.0.6 on WordPress authorization
A vulnerability was found in sparklewpthemes Fitness FSE Plugin up to 1.0.6 on WordPress and classified as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to missing authorization.
This vulnerability appears as CVE-2026-25394. The attack may be performed from remote. There is no available exploit.