First published: Thu Apr 17 2025(Updated: )
Missing Authorization vulnerability in mingocommerce Delete All Posts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Delete All Posts: from n/a through 1.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Delete All Posts | <=1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23773 has been classified as a high-severity vulnerability due to its potential to allow unauthorized deletion of posts.
To fix CVE-2025-23773, update the Delete All Posts plugin to version 1.1.2 or later where the vulnerability has been addressed.
CVE-2025-23773 affects the Delete All Posts plugin versions up to and including 1.1.1.
CVE-2025-23773 is a Missing Authorization vulnerability that allows exploitation through incorrectly configured access control levels.
Users of the Delete All Posts plugin on WordPress running versions up to 1.1.1 are impacted by CVE-2025-23773.