CVE-2025-47465: WordPress Blocksy theme <= 2.0.97 - Broken Access Control Vulnerability
Missing Authorization vulnerability in CreativeThemes Blocksy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Blocksy: from n/a through 2.0.97.
Other sources
Missing Authorization vulnerability in creativethemeshq Blocksy blocksy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blocksy: from n/a through <= 2.0.97.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47465?
CVE-2025-47465 is classified as a critical vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-47465?
To mitigate CVE-2025-47465, update CreativeThemes Blocksy to version 2.0.98 or later immediately.
What types of systems are affected by CVE-2025-47465?
CVE-2025-47465 affects CreativeThemes Blocksy versions up to 2.0.97.
What can attackers do by exploiting CVE-2025-47465?
Attackers exploiting CVE-2025-47465 can bypass access controls and gain unauthorized permissions within affected systems.
Is any user action required to protect against CVE-2025-47465?
Yes, all users of CreativeThemes Blocksy should update their software to the latest version to protect against CVE-2025-47465.