CVE-2025-25110: WordPress Event Kikfyre plugin <= 2.1.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in Metagauss Event Kikfyre kikfyre-events-calendar-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Kikfyre: from n/a through <= 2.1.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Event Kikfyre plugin (kikfyre-events-calendar-tickets)to a version that resolves this vulnerability.Fixed in 2.1.8
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25110?
CVE-2025-25110 is classified as a critical severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-25110?
To fix CVE-2025-25110, update Metagauss Event Kikfyre to the latest version that addresses the access control issue.
What types of systems are affected by CVE-2025-25110?
CVE-2025-25110 affects Metagauss Event Kikfyre versions up to and including 2.1.8.
What are the potential risks of CVE-2025-25110?
The potential risks of CVE-2025-25110 include unauthorized access to sensitive data and actions by unprivileged users.
Is CVE-2025-25110 related to misconfigured access controls?
Yes, CVE-2025-25110 is specifically a missing authorization vulnerability linked to incorrectly configured access control security levels.