First published: Thu Apr 17 2025(Updated: )
Missing Authorization vulnerability in Mat Bao Corporation WP Helper Premium allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP Helper Premium: from n/a through 4.6.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WP Helper Premium | <=4.6.1 | |
WordPress WP Helper Premium | <=4.6.1 |
Update the WordPress WP Helper Premium plugin to the latest available version (at least 4.6.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24737 is rated as a high severity vulnerability due to its potential for unauthorized access to sensitive functionalities.
To fix CVE-2025-24737, update the WP Helper Premium plugin to version 4.6.2 or later.
CVE-2025-24737 affects functionalities that are not properly constrained by Access Control Lists (ACLs) within the WP Helper Premium plugin.
Anyone using WP Helper Premium version 4.6.1 or earlier is affected by CVE-2025-24737.
As a temporary workaround for CVE-2025-24737, users should restrict access to the plugin's functionalities until an update can be applied.