First published: Tue Jan 21 2025(Updated: )
Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline – Application Form Builder and Manager: from n/a through 2.6.7.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Farhan Noor ApplyOnline | <=2.6.7.1 | |
WordPress ApplyOnline Plugin | <=2.6.7.1 |
Update the WordPress ApplyOnline – Application Form Builder and Manager wordpress plugin to the latest available version (at least 2.6.7.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22721 is categorized as a critical vulnerability due to its potential to exploit incorrectly configured access control levels.
To fix CVE-2025-22721, update Farhan Noor ApplyOnline to the latest version that addresses this missing authorization issue.
CVE-2025-22721 affects Farhan Noor ApplyOnline – Application Form Builder and Manager versions up to and including 2.6.7.1.
CVE-2025-22721 can allow unauthorized access to sensitive data and functionalities due to improper access control configurations.
The vendor associated with CVE-2025-22721 is Farhan Noor, related to the ApplyOnline – Application Form Builder and Manager.