CVE-2025-48242: WordPress Legal Pages plugin <= 1.4.5 - Broken Access Control Vulnerability
Missing Authorization vulnerability in wpWax Legal Pages allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Legal Pages: from n/a through 1.4.5.
Other sources
Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Legal Pages: from n/a through <= 1.4.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48242?
CVE-2025-48242 is classified as a Missing Authorization vulnerability that poses a significant security risk due to incorrectly configured access control levels.
How do I fix CVE-2025-48242?
To fix CVE-2025-48242, update wpWax Legal Pages to the latest version beyond 1.4.5 to ensure proper access control configurations.
What versions of Legal Pages are affected by CVE-2025-48242?
CVE-2025-48242 affects versions of wpWax Legal Pages up to and including 1.4.5.
What types of attacks can CVE-2025-48242 enable?
CVE-2025-48242 can enable unauthorized access to sensitive pages by exploiting the missing authorization checks.
Who is at risk from CVE-2025-48242?
Users of wpWax Legal Pages versions 1.4.5 and earlier are at a heightened risk of exploitation due to CVE-2025-48242.