First published: Tue Jan 07 2025(Updated: )
Missing Authorization vulnerability in Lenderd 1003 Mortgage Application allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects 1003 Mortgage Application: from n/a through 1.87.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenderd 1003 Mortgage Application | <=1.87 | |
WordPress 1003 Mortgage Application plugin | <=1.87 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22592 has been classified as a high severity vulnerability due to the potential for exploitation through unauthorized access.
To fix CVE-2025-22592, update the Lenderd 1003 Mortgage Application to version 1.88 or later, which contains the necessary patches.
CVE-2025-22592 affects functionality in the Lenderd 1003 Mortgage Application that is not properly constrained by Access Control Lists (ACLs), allowing unauthorized access.
Versions of the Lenderd 1003 Mortgage Application from n/a through 1.87 are vulnerable to CVE-2025-22592.
Yes, the WordPress 1003 Mortgage Application plugin versions up to 1.87 are also affected by CVE-2025-22592.