CVE-2025-30990: WordPress ThemeHunk plugin <= 1.2.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in ThemeHunk ThemeHunk themehunk-megamenu-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeHunk: from n/a through <= 1.2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30990?
CVE-2025-30990 is classified as a missing authorization vulnerability that can lead to unauthorized access due to incorrectly configured access control security levels.
How do I fix CVE-2025-30990?
To fix CVE-2025-30990, ensure that access control settings are correctly configured and update to the latest version of ThemeHunk beyond 1.1.1.
Who is affected by CVE-2025-30990?
CVE-2025-30990 affects users of the ThemeHunk theme on WordPress, specifically versions up to and including 1.1.1.
What types of attacks could exploit CVE-2025-30990?
CVE-2025-30990 could be exploited to gain unauthorized access to restricted areas of a WordPress site using the ThemeHunk theme.
Is there a known exploit for CVE-2025-30990?
Yes, there are known exploit scenarios for CVE-2025-30990 that involve leveraging misconfigured access control settings to perform unauthorized actions.