CVE-2025-39454: WordPress Name Directory plugin <= 1.30.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= 1.30.0.
Other sources
Missing Authorization vulnerability in Jeroen Peters Name Directory.This issue affects Name Directory: from n/a through 1.30.0.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39454?
CVE-2025-39454 is rated as a high severity vulnerability due to the missing authorization features.
How do I fix CVE-2025-39454?
To fix CVE-2025-39454, update Jeroen Peters Name Directory plugin to version 1.30.1 or later.
What systems are affected by CVE-2025-39454?
CVE-2025-39454 affects versions up to and including 1.30.0 of the Jeroen Peters Name Directory and its associated WordPress plugin.
What type of vulnerability is CVE-2025-39454?
CVE-2025-39454 is classified as a missing authorization vulnerability.
Can CVE-2025-39454 lead to data exposure?
Yes, CVE-2025-39454 can potentially allow unauthorized access to sensitive information.