First published: Thu Apr 17 2025(Updated: )
Missing Authorization vulnerability in Themefic Instantio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Instantio: from n/a through 3.3.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themefic Instantio | >n/a<=3.3.7 | |
WordPress Instantio | <=3.3.7 |
Update the WordPress Instantio plugin to the latest available version (at least 3.3.8).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24581 has been classified as a high-severity vulnerability due to its potential impact on unauthorized access.
To mitigate CVE-2025-24581, upgrade Themefic Instantio to version 3.3.8 or later, which addresses the missing authorization vulnerability.
CVE-2025-24581 affects Themefic Instantio from version n/a up to and including 3.3.7.
Yes, CVE-2025-24581 impacts WordPress users utilizing the Instantio plugin up to version 3.3.7.
CVE-2025-24581 is classified as a Missing Authorization vulnerability related to incorrectly configured access control levels.