CVE-2025-47485: WordPress Cozy Blocks plugin <= 2.1.22 - Broken Access Control Vulnerability
Missing Authorization vulnerability in CozyThemes Cozy Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cozy Blocks: from n/a through 2.1.22.
Other sources
Missing Authorization vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through <= 2.1.22.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47485?
CVE-2025-47485 has a critical severity due to its potential for unauthorized access and exploitation.
How do I fix CVE-2025-47485?
To fix CVE-2025-47485, upgrade Cozy Blocks to version 2.1.23 or later where the vulnerability is patched.
What versions are affected by CVE-2025-47485?
CVE-2025-47485 affects Cozy Blocks versions up to and including 2.1.22.
What can happen if CVE-2025-47485 is exploited?
Exploitation of CVE-2025-47485 can lead to unauthorized access and manipulation of data due to misconfigured access controls.
Who is affected by CVE-2025-47485?
Users of Cozy Blocks and WordPress Cozy Blocks versions up to 2.1.22 are affected by CVE-2025-47485.