First published: Thu Apr 03 2025(Updated: )
Missing Authorization vulnerability in Think201 Clients allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Clients: from n/a through 1.1.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Think201 | >=n/a<=1.1.4 | |
WordPress Clients plugin | <=1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31746 is classified as a missing authorization vulnerability, which can lead to unauthorized access and exploitation of incorrectly configured access controls.
To fix CVE-2025-31746, ensure that access control security levels are properly configured in Think201 Clients or the WordPress Clients plugin.
CVE-2025-31746 affects Think201 Clients from n/a up to version 1.1.4 and the WordPress Clients plugin up to version 1.1.4.
Yes, CVE-2025-31746 can potentially lead to data breaches due to its nature of enabling unauthorized access.
If your application is vulnerable to CVE-2025-31746, it is crucial to update to a secure version and review access control settings immediately.