CVE-2025-30624: WordPress WordLift plugin <= 3.54.4 - Broken Access Control Vulnerability
Missing Authorization vulnerability in WordLift WordLift allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordLift: from n/a through 3.54.4.
Other sources
Missing Authorization vulnerability in WordLift WordLift wordlift allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordLift: from n/a through <= 3.54.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30624?
CVE-2025-30624 is classified as a Missing Authorization vulnerability that can lead to exploitation due to incorrectly configured access controls.
How do I fix CVE-2025-30624?
To fix CVE-2025-30624, update WordLift to the latest version beyond 3.54.4 to ensure proper access control configurations.
Which versions of WordLift are affected by CVE-2025-30624?
CVE-2025-30624 affects WordLift versions up to and including 3.54.4.
What are the potential impacts of CVE-2025-30624?
The potential impacts of CVE-2025-30624 include unauthorized access to restricted functionalities within the WordLift plugin.
Is CVE-2025-30624 specific to any platform?
Yes, CVE-2025-30624 specifically affects the WordLift plugin across its integration with WordPress.