First published: Mon Mar 31 2025(Updated: )
Missing Authorization vulnerability in Jaap Jansma Connector to CiviCRM with CiviMcRestFace allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Connector to CiviCRM with CiviMcRestFace: from n/a through 1.0.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Connector to CiviCRM with CiviMcRestFace | >=1.0.0<=1.0.9 | |
Jaap Jansma Connector to CiviCRM with CiviMcRestFace | <=1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31618 is classified as a Missing Authorization vulnerability that may lead to the exploitation of incorrectly configured access controls.
To fix CVE-2025-31618, it is recommended to update the Jaap Jansma Connector to CiviCRM with CiviMcRestFace to version 1.0.10 or later.
CVE-2025-31618 affects Jaap Jansma Connector to CiviCRM with CiviMcRestFace versions from 1.0.0 through 1.0.9.
The impact of CVE-2025-31618 includes unauthorized access due to poorly configured access control security levels.
The vendor associated with CVE-2025-31618 is Jaap Jansma, the developer of the Connector to CiviCRM with CiviMcRestFace.