First published: Thu Apr 03 2025(Updated: )
Missing Authorization vulnerability in OTWthemes Widget Manager Light allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Widget Manager Light: from n/a through 1.18.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
OTWthemes Widget Manager Light | <=1.18 | |
WordPress Widget Manager Light | <=1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31768 is classified as a Missing Authorization vulnerability which can lead to unauthorized access to functionality.
To fix CVE-2025-31768, update the OTWthemes Widget Manager Light to a version beyond 1.18 that addresses the access control issue.
CVE-2025-31768 affects users of OTWthemes Widget Manager Light version 1.18 and earlier.
Exploiting CVE-2025-31768, attackers may gain access to functions that are not properly constrained by Access Control Lists (ACLs).
Currently, there are no known effective workarounds for CVE-2025-31768 other than applying the necessary update.