First published: Thu Apr 03 2025(Updated: )
Missing Authorization vulnerability in jeffikus WooTumblog allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooTumblog: from n/a through 2.1.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WooTumblog | <=2.1.4 | |
WooTumblog | <=2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-31729 is considered medium due to the risk of unauthorized access through misconfigured security levels.
To fix CVE-2025-31729, you should update the WooTumblog plugin to version 2.1.5 or later, ensuring proper access control settings.
The risks associated with CVE-2025-31729 include unauthorized access to sensitive data and potential exploitation of administrative functions.
CVE-2025-31729 affects versions of WooTumblog from n/a up to and including 2.1.4.
The vendor responsible for CVE-2025-31729 is Jeffikus, the creator of the WooTumblog plugin.