References https://nvd.nist.gov/vuln/detail/CVE-2025-3604 https://github.com/Nxploited/CVE-2025-3604 https://hackhalt.com/threat/cve-2025-3604-flynax-bridge/ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/flynax-bridge/flynax-bridge-220-unauthenticated-arbitrary-user-deletion https://avd.aquasec.com/nvd/2025/cve-2025-3604/ https://app.opencve.io/cve/CVE-2025-3604 https://www.appsecure.security/vulnerability-database/cve-2025-3604/ https://www.sentinelone.com/vulnerability-database/cve-2025-3604/ https://www.ameeba.com/blog/cve-2025-3604-critical-privilege-escalation-vulnerability-in-flynax-bridge-plugin-for-wordpress/ https://github.com/advisories/GHSA-8xcw-x64j-h58v https://avd.aliyun.com/detail?id=AVD-2025-3604 https://cve.imfht.com/detail/CVE-2025-3604?lang=en
Related VulnerabilitiesPoCCVE-2026-59726: ruflo MCP Bridge - Unauthenticated RCE via terminal_executeWordPress Time Capsule /wp-tcapsule-bridge/upload/php/index.php 文件上传漏洞(CVE-2024-8856)Homebridge Config UI X /api/auth/login 默认口令漏洞PoChomebridge-default-login: Homebridge - Default Admin CredentialsHomebridge存在默认口令泛微云桥e-Bridge /wxthirdapi/sendWxMsg SQL 注入漏洞PoC泛微云桥 e-Bridge sendWxMsg 接口存在SQL注入漏洞PoChomebridge-unfinished-install: Homebridge - Unfinished Installationecology-ebridge-addtaste-sqli: 泛微云桥 taste/addTaste SQL注入PoCCVE-2020-11853: Micro Focus Operations Bridge Manager <=2020.05 - Remote Code ExecutionPoCCVE-2021-22502: Micro Focus Operations Bridge Reporter - Remote Code ExecutionPoCCVE-2021-25112: WordPress WHMCS Bridge <6.4b - Cross-Site ScriptingPoCCVE-2025-4008: MeteoBridge <= 6.1 - Remote Code Execution