CVE-2025-22647: WordPress AIO Performance Profiler plugin <= 1.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in smackcoders AIO Performance Profiler, Monitor, Optimize, Compress & Debug allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through 1.2.
Other sources
Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through <= 1.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22647?
CVE-2025-22647 is considered a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-22647?
To fix CVE-2025-22647, update the AIO Performance Profiler, Monitor, Optimize, Compress & Debug to the latest version released after the vulnerability was disclosed.
What products are affected by CVE-2025-22647?
CVE-2025-22647 affects the Smackcoders AIO Performance Profiler and its WordPress variant up to version 1.2.
What type of vulnerability is CVE-2025-22647?
CVE-2025-22647 is a missing authorization vulnerability that allows exploitation through incorrectly configured access control.
Can CVE-2025-22647 be exploited remotely?
Yes, CVE-2025-22647 can be exploited remotely, allowing attackers to gain unauthorized access if the system is not properly secured.