CVE-2025-7504 | Friends Plugin 3.5.1 on WordPress query_vars deserialization (EUVD-2025-21210)
A vulnerability classified as critical was found in Friends Plugin 3.5.1 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation of the argument query_vars leads to deserialization.
This vulnerability is known as CVE-2025-7504. The attack can be launched remotely. There is no exploit available.