CVE-2025-49234: WordPress WP Dummy Content Generator plugin <= 3.4.6 - Arbitrary User Deletion vulnerability
Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Dummy Content Generator: from n/a through 3.4.6.
Other sources
Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through <= 3.4.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49234?
CVE-2025-49234 has been classified as a high severity vulnerability due to its potential for unauthorized access and data manipulation.
How do I fix CVE-2025-49234?
To fix CVE-2025-49234, it is recommended to update WP Dummy Content Generator to version 3.4.7 or newer.
What versions of Deepak Anand WP Dummy Content Generator are affected by CVE-2025-49234?
CVE-2025-49234 affects all versions of Deepak Anand WP Dummy Content Generator up to and including version 3.4.6.
What type of vulnerability is CVE-2025-49234?
CVE-2025-49234 is a missing authorization vulnerability that allows exploitation of improperly configured access controls.
Can CVE-2025-49234 lead to data breaches?
Yes, CVE-2025-49234 can potentially lead to data breaches by allowing unauthorized users to access or manipulate content.