CVE-2025-39456: WordPress WP Logger plugin <= 2.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in iTRON WP Logger allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logger: from n/a through 2.2.
Other sources
Missing Authorization vulnerability in iTRON WP Logger wp-data-logger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Logger: from n/a through <= 2.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39456?
The severity of CVE-2025-39456 is rated as high due to its potential for unauthorized access.
How do I fix CVE-2025-39456?
To fix CVE-2025-39456, update the WP Logger plugin to the latest version beyond 2.2 that addresses access control issues.
What systems are affected by CVE-2025-39456?
CVE-2025-39456 affects WP Logger versions up to and including 2.2.
What kind of vulnerability is CVE-2025-39456?
CVE-2025-39456 is a Missing Authorization vulnerability that allows exploitation through incorrectly configured access controls.
What are the risks associated with CVE-2025-39456?
The risks associated with CVE-2025-39456 include potential unauthorized access to sensitive data or functionalities within the affected system.