CVE-2025-49874: WordPress Arconix FAQ plugin <= 1.9.6 - Broken Access Control Vulnerability
Missing Authorization vulnerability in tychesoftwares Arconix FAQ allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Arconix FAQ: from n/a through 1.9.6.
Other sources
Missing Authorization vulnerability in tychesoftwares Arconix FAQ arconix-faq allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arconix FAQ: from n/a through <= 1.9.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49874?
CVE-2025-49874 is a critical severity vulnerability due to missing authorization that allows unauthorized access to functionalities.
How do I fix CVE-2025-49874?
To fix CVE-2025-49874, update the Arconix FAQ plugin to version 1.9.7 or later.
Which versions of Arconix FAQ are affected by CVE-2025-49874?
CVE-2025-49874 affects all versions of Arconix FAQ from an unknown release up to and including version 1.9.6.
What kind of exploit can occur due to CVE-2025-49874?
Exploit of CVE-2025-49874 can lead to unauthorized access to restricted functionalities within the Arconix FAQ plugin.
Who is affected by the CVE-2025-49874 vulnerability?
Users of the Tyche Softwares Arconix FAQ plugin on WordPress who have not updated past version 1.9.6 are affected by CVE-2025-49874.