First published: Thu Apr 03 2025(Updated: )
Missing Authorization vulnerability in gunnarpayday Payday allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Payday: from n/a through 3.3.12.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gunnarpayday Payday | >=3.3.12 | |
WordPress Payday Plugin | <=3.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31876 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive functionality.
To fix CVE-2025-31876, ensure that you update the GunnarPayday Payday or WordPress Payday plugin to the latest version that addresses this vulnerability.
CVE-2025-31876 affects GunnarPayday Payday from n/a through version 3.3.12 and the WordPress Payday plugin up to version 3.3.12.
CVE-2025-31876 is a Missing Authorization vulnerability that results from incorrectly configured access control security levels.
Users of GunnarPayday Payday or the WordPress Payday plugin within the specified versions are at risk of being impacted by CVE-2025-31876.