CVE-2025-22629: WordPress iNET Webkit Plugin <= 1.2.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in iNET iNET Webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iNET Webkit: from n/a through 1.2.2.
Other sources
Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iNET Webkit: from n/a through <= 1.2.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22629?
CVE-2025-22629 is classified as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-22629?
To fix CVE-2025-22629, update iNET Webkit and the WordPress iNET Webkit Plugin to version 1.2.3 or later.
What kind of vulnerability is CVE-2025-22629?
CVE-2025-22629 is a missing authorization vulnerability that allows access to functionalities not properly constrained by Access Control Lists (ACLs).
Which versions of iNET Webkit are affected by CVE-2025-22629?
iNET Webkit versions up to and including 1.2.2 are affected by CVE-2025-22629.
Can CVE-2025-22629 affect WordPress sites?
Yes, CVE-2025-22629 can affect WordPress sites using the iNET Webkit Plugin up to version 1.2.2.