CVE-2025-24607: WordPress IdeaPush plugin <= 8.71 - Broken Access Control vulnerability
Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through <= 8.71.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24607?
CVE-2025-24607 is classified as a high severity vulnerability due to its potential to allow unauthorized access and manipulation of sensitive data.
How do I fix CVE-2025-24607?
To fix CVE-2025-24607, ensure that access control security levels are correctly configured in your IdeaPush installation, and update to the latest version.
What versions of IdeaPush are affected by CVE-2025-24607?
CVE-2025-24607 affects IdeaPush versions up to and including 8.71.
What type of vulnerability is CVE-2025-24607?
CVE-2025-24607 is a Missing Authorization vulnerability that can be exploited due to incorrectly configured access control security levels.
Can CVE-2025-24607 be exploited remotely?
Yes, CVE-2025-24607 can be exploited remotely, exposing the affected systems to unauthorized access.