First published: Tue Apr 01 2025(Updated: )
Missing Authorization vulnerability in EXEIdeas International WP AutoKeyword allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP AutoKeyword: from n/a through 1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP AutoKeyword | <=1.0 | |
WP AutoKeyword | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31870 has been classified as a critical vulnerability due to its potential to allow unauthorized access and manipulation of sensitive user data.
To fix CVE-2025-31870, it is recommended to update the WP AutoKeyword plugin to the latest version, as older versions are vulnerable due to improper authorization controls.
CVE-2025-31870 affects users of WP AutoKeyword plugin versions up to and including 1.0 on WordPress sites, particularly where access controls are misconfigured.
CVE-2025-31870 is a missing authorization vulnerability that exploits incorrectly configured access control security levels.
Yes, exploiters can potentially utilize CVE-2025-31870 to gain unauthorized access and perform actions without proper authentication, making it a severe risk.