CVE-2025-39545: WordPress REST API Authentication plugin <= 3.6.3 - Settings Change Vulnerability
Missing Authorization vulnerability in miniOrange WordPress REST API Authentication allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress REST API Authentication: from n/a through 3.6.3.
Other sources
Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39545?
CVE-2025-39545 is classified as a high-severity vulnerability due to its potential for unauthorized access and exploitation of user data.
How do I fix CVE-2025-39545?
To fix CVE-2025-39545, update the miniOrange WordPress REST API Authentication plugin to the latest version beyond 3.6.3.
What are the consequences of CVE-2025-39545?
Exploiting CVE-2025-39545 can lead to unauthorized access to sensitive data through incorrectly configured access control security levels.
Who is affected by CVE-2025-39545?
CVE-2025-39545 affects users of the miniOrange WordPress REST API Authentication plugin in versions from n/a to 3.6.3.
Is there a workaround for CVE-2025-39545?
A temporary workaround for CVE-2025-39545 includes reviewing and hardening your WordPress access control settings until a patch can be applied.