CVE-2025-39460: WordPress Eduma theme <= 5.6.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in ThimPress Eduma allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eduma: from n/a through 5.6.4.
Other sources
Missing Authorization vulnerability in ThimPress Eduma eduma allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eduma: from n/a through <= 5.6.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39460?
CVE-2025-39460 has been assessed as a high severity vulnerability due to its potential to allow unauthorized access to sensitive features.
How do I fix CVE-2025-39460?
To fix CVE-2025-39460, update ThimPress Eduma to version 5.6.5 or later where the vulnerability is addressed.
What versions of Eduma are affected by CVE-2025-39460?
CVE-2025-39460 affects all versions of Eduma up to and including version 5.6.4.
What is the impact of CVE-2025-39460?
The impact of CVE-2025-39460 allows attackers to exploit incorrectly configured access controls, potentially leading to unauthorized actions.
Who should be concerned about CVE-2025-39460?
All users and administrators of ThimPress Eduma and WordPress Eduma versions up to 5.6.4 should be concerned about CVE-2025-39460.