CVE-2025-24643: WordPress WPGuppy plugin <= 1.1.0 - Broken Authentication vulnerability
Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPGuppy: from n/a through <= 1.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24643?
The severity of CVE-2025-24643 is classified as high due to missing authorization vulnerabilities that can lead to unauthorized access.
How do I fix CVE-2025-24643?
To fix CVE-2025-24643, update WPGuppy to the latest version beyond 1.1.0 to ensure proper access control configurations.
What versions of WPGuppy are affected by CVE-2025-24643?
CVE-2025-24643 affects all versions of WPGuppy up to and including 1.1.0.
What type of vulnerability is CVE-2025-24643?
CVE-2025-24643 is a missing authorization vulnerability that allows exploitation of incorrectly configured access controls.
Can CVE-2025-24643 be exploited remotely?
Yes, CVE-2025-24643 can be exploited remotely, as it involves authorization bypass that can be triggered over the internet.