CVE-2025-39535: WordPress Vitepos plugin <= 3.1.7 - Broken Authentication Vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos allows Authentication Abuse. This issue affects Vitepos: from n/a through 3.1.7.
Other sources
Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authentication Abuse.This issue affects Vitepos: from n/a through <= 3.1.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39535?
CVE-2025-39535 is classified as an Authentication Bypass vulnerability that allows for Authentication Abuse.
How do I fix CVE-2025-39535?
To fix CVE-2025-39535, upgrade Vitepos to the latest version beyond 3.1.7.
Which versions of Vitepos are affected by CVE-2025-39535?
CVE-2025-39535 affects Vitepos versions from any version to 3.1.7.
What are the potential impacts of CVE-2025-39535?
The potential impacts of CVE-2025-39535 include unauthorized access and the ability to perform actions on behalf of legitimate users.
Is CVE-2025-39535 a common vulnerability?
CVE-2025-39535 is specific to the Vitepos application and may not be as widely known as other common vulnerabilities.