First published: Thu Mar 27 2025(Updated: )
Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for WPForms: from n/a through 5.3.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPForms PDF for WPForms | <=5.3.0 |
Update the WordPress PDF for WPForms plugin to the latest available version (at least 5.3.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30767 is classified as a missing authorization vulnerability that can allow unauthorized access to functionalities in the PDF for WPForms plugin.
To fix CVE-2025-30767, ensure that you update to the latest version of the PDF for WPForms plugin that addresses the missing authorization issue.
CVE-2025-30767 affects all versions of PDF for WPForms up to and including version 5.3.0.
To mitigate CVE-2025-30767, implement proper access controls and regularly review your plugin configurations, alongside updating to a patched version.
Yes, CVE-2025-30767 poses a risk of unauthorized data exposure due to incorrectly configured access control security levels.