First published: Tue Jan 07 2025(Updated: )
Missing Authorization vulnerability in Lenderd 1003 Mortgage Application allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1003 Mortgage Application: from n/a through 1.87.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenderd 1003 Mortgage Application | >=n/a<=1.87 | |
WordPress 1003 Mortgage Application plugin | <=1.87 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22591 has been classified as a high-severity vulnerability due to its potential for exploitation involving missing authorization controls.
To fix CVE-2025-22591, update the Lenderd 1003 Mortgage Application or the WordPress 1003 Mortgage Application plugin to the latest version beyond 1.87.
CVE-2025-22591 affects Lenderd 1003 Mortgage Application from n/a to 1.87 and the WordPress 1003 Mortgage Application plugin up to version 1.87.
CVE-2025-22591 is a missing authorization vulnerability that allows unauthorized access due to incorrectly configured access control security levels.
Currently, the best approach to mitigate CVE-2025-22591 is to update to secure versions as no official workaround exists for bypassing the authorization issues.