First published: Fri Feb 14 2025(Updated: )
Missing Authorization vulnerability in Mark Winiarski WPLingo allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPLingo: from n/a through 1.1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WPLingo | >=1.1.2 | |
WordPress | <=1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23534 is considered a critical vulnerability due to its potential for unauthorized access and exploitation.
To fix CVE-2025-23534, it is recommended to update WPLingo to a version higher than 1.1.2 which addresses the missing authorization issue.
CVE-2025-23534 is caused by incorrectly configured access control security levels in the WPLingo plugin.
CVE-2025-23534 affects WPLingo versions from an unspecified version to 1.1.2 inclusive.
Yes, exploiting CVE-2025-23534 can lead to unauthorized actions and potentially result in data breaches.