CVE-2025-12167: Contact Form 7 AWeber Extension <= 0.1.42 - Missing Authorization to Authenticated (Subscriber+) Log Reset
The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpajaxaweberlogreset' AJAX endpoint in all versions up to, and including, 0.1.42. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the AWeber logs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12167?
The severity of CVE-2025-12167 is considered moderate due to its potential for unauthorized data modification.
How do I fix CVE-2025-12167?
To fix CVE-2025-12167, update the Contact Form 7 AWeber Extension plugin to version 0.1.43 or later.
Who is affected by CVE-2025-12167?
CVE-2025-12167 affects all versions of the Contact Form 7 AWeber Extension plugin up to and including version 0.1.42.
What type of attack does CVE-2025-12167 enable?
CVE-2025-12167 enables authenticated attackers to modify data without proper authorization.
What software is involved in CVE-2025-12167?
CVE-2025-12167 involves the Contact Form 7 AWeber Extension plugin for WordPress.