CVE-2025-27008: WordPress Unlimited Timeline < 1.6.1 - Broken Access Control Vulnerability
Missing Authorization vulnerability in NotFound Unlimited Timeline unlimited-timeline allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Unlimited Timeline: from n/a through < 1.6.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27008?
CVE-2025-27008 is classified as a missing authorization vulnerability that may expose certain functionalities due to improperly constrained access controls.
How do I fix CVE-2025-27008?
To remediate CVE-2025-27008, update the WordPress Unlimited Timeline plugin to the latest version that addresses the vulnerability.
What are the potential impacts of CVE-2025-27008?
The potential impact of CVE-2025-27008 includes unauthorized access to functionalities that should be restricted by access control lists (ACLs).
Which versions of WordPress Unlimited Timeline are affected by CVE-2025-27008?
CVE-2025-27008 affects WordPress Unlimited Timeline version 1.6.1 and potentially earlier versions.
Is CVE-2025-27008 a common vulnerability in WordPress plugins?
Missing authorization vulnerabilities like CVE-2025-27008 are relatively common in WordPress plugins and highlight the importance of proper access control implementations.