Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

WordPress Allows Attackers to Crash Server with Malicious Input

CVE-2025-59603
Summary

A security issue in WordPress can cause a server to crash if it receives invalid data. This can happen if an attacker sends malicious input to the server. To stay safe, update WordPress to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
qualcomm sd865_5g_firmware All versions
qualcomm snapdragon_xr2_5g_platform_firmware All versions
qualcomm snapdragon_xr2\+_gen_1_platform_firmware All versions
qualcomm sxr2230p_firmware All versions
qualcomm sxr2250p_firmware All versions
qualcomm wcd9378c_firmware All versions
qualcomm wcd9380_firmware All versions
qualcomm wcd9385_firmware All versions
qualcomm wsa8810_firmware All versions
qualcomm wsa8815_firmware All versions
qualcomm wsa8830_firmware All versions
qualcomm wsa8832_firmware All versions
qualcomm wsa8835_firmware All versions
qualcomm wsa8840_firmware All versions
qualcomm wsa8845_firmware All versions
qualcomm wsa8845h_firmware All versions
qualcomm x2000077_firmware All versions
qualcomm x2000086_firmware All versions
qualcomm x2000090_firmware All versions
qualcomm x2000092_firmware All versions
qualcomm x2000094_firmware All versions
qualcomm xg101002_firmware All versions
qualcomm xg101032_firmware All versions
qualcomm xg101039_firmware All versions
qualcomm cologne_firmware All versions
qualcomm fastconnect_6900_firmware All versions
qualcomm fastconnect_7800_firmware All versions
qualcomm qca0000_firmware All versions
qualcomm sc8380xp_firmware All versions
Original title
Memory Corruption when processing invalid user address with nonstandard buffer address.
Original description
Memory Corruption when processing invalid user address with nonstandard buffer address.
nvd CVSS3.1 7.8
Vulnerability type
CWE-787 Out-of-bounds Write
Published: 2 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026