First published: Tue Apr 01 2025(Updated: )
Missing Authorization vulnerability in PickPlugins Question Answer allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Question Answer: from n/a through 1.2.70.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Question Answer | <=1.2.70 | |
WordPress Question Answer Plugin | <=1.2.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31810 is classified as a missing authorization vulnerability that can lead to unauthorized access.
To fix CVE-2025-31810, update the PickPlugins Question Answer plugin to version 1.2.71 or higher, which addresses the issue.
CVE-2025-31810 affects all versions of the PickPlugins Question Answer plugin up to and including version 1.2.70.
CVE-2025-31810 allows access to functionality that is not properly constrained by access control lists (ACLs).
Yes, CVE-2025-31810 can be exploited to gain unauthorized access to functionalities if proper controls are not in place.