CVE-2025-39412: WordPress Master Slider plugin <= 3.11.0 - Broken Access Control vulnerability
Published May 19, 2025
·Updated
Missing Authorization vulnerability in averta Master Slider master-slider.This issue affects Master Slider: from n/a through <= 3.11.0.
Affected Software
4 affected components
WordPress Master Slider>=3.10.8
WordPress Master Slider<=3.10.8
WordPress Master Slider<=3.10.8
averta Master Slider Wordpress<=3.10.8
Event History
May 19, 2025
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-39412?
CVE-2025-39412 has a medium severity rating due to its potential for unauthorized access.
2
How do I fix CVE-2025-39412?
To fix CVE-2025-39412, update the Averta Master Slider to version 3.10.9 or later.
3
What versions of Master Slider are affected by CVE-2025-39412?
CVE-2025-39412 affects all versions of Averta Master Slider from n/a to 3.10.8.
4
What type of vulnerability is CVE-2025-39412?
CVE-2025-39412 is classified as a Missing Authorization vulnerability.
5
What impact does CVE-2025-39412 have on my website?
CVE-2025-39412 may allow attackers to gain unauthorized access to sensitive areas of your website.