CVE-2025-39511: WordPress Pinterest Automatic Pin plugin <= 4.19.0 - Broken Access Control Vulnerability
Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pinterest Automatic Pin: from n/a through 4.18.2.
Other sources
Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinterest Automatic Pin: from n/a through <= 4.19.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39511?
CVE-2025-39511 is classified as a missing authorization vulnerability that can lead to unauthorized access due to improperly configured security levels.
How do I fix CVE-2025-39511?
To fix CVE-2025-39511, ensure that you update the Pinterest Automatic Pin plugin to the latest version past 4.18.2 and review your access control settings.
What versions of Pinterest Automatic Pin are affected by CVE-2025-39511?
CVE-2025-39511 affects Pinterest Automatic Pin versions from n/a up to and including 4.18.2.
What potential risks does CVE-2025-39511 pose?
CVE-2025-39511 poses risks of unauthorized access to sensitive data or functionalities due to incorrectly configured access controls.
Who is impacted by CVE-2025-39511?
Anyone using the Pinterest Automatic Pin plugin for WordPress versions up to 4.18.2 is impacted by CVE-2025-39511.