CVE-2025-31810: WordPress Question Answer plugin <= 1.2.73 - Broken Access Control vulnerability
Missing Authorization vulnerability in PickPlugins Question Answer question-answer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Question Answer: from n/a through <= 1.2.73.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31810?
CVE-2025-31810 is classified as a missing authorization vulnerability that can lead to unauthorized access.
How do I fix CVE-2025-31810?
To fix CVE-2025-31810, update the PickPlugins Question Answer plugin to version 1.2.71 or higher, which addresses the issue.
What versions of the PickPlugins Question Answer are affected by CVE-2025-31810?
CVE-2025-31810 affects all versions of the PickPlugins Question Answer plugin up to and including version 1.2.70.
What functionality is impacted by CVE-2025-31810?
CVE-2025-31810 allows access to functionality that is not properly constrained by access control lists (ACLs).
Is the CVE-2025-31810 vulnerability exploitable?
Yes, CVE-2025-31810 can be exploited to gain unauthorized access to functionalities if proper controls are not in place.