CVE-2025-49900: WordPress Advanced scrollbar plugin <= 1.1.8 - Privilege Escalation vulnerability
Published Nov 6, 2025
·Updated
Incorrect Privilege Assignment vulnerability in bPlugins Advanced scrollbar advanced-scrollbar allows Privilege Escalation.This issue affects Advanced scrollbar: from n/a through <= 1.1.8.
Affected Software
2 affected components
bPlugins Advanced scrollbar<=1.1.8
WordPress Advanced scrollbar<=1.1.8
Event History
Nov 6, 2025
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49900?
CVE-2025-49900 has a high severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2025-49900?
To fix CVE-2025-49900, upgrade the bPlugins Advanced scrollbar plugin to version 1.1.9 or later.
3
Who is affected by CVE-2025-49900?
CVE-2025-49900 affects users of the bPlugins Advanced scrollbar plugin version 1.1.8 and earlier.
4
What type of vulnerability is CVE-2025-49900?
CVE-2025-49900 is classified as an incorrect privilege assignment vulnerability.
5
What can attackers do with CVE-2025-49900?
Attackers exploiting CVE-2025-49900 can achieve privilege escalation, potentially allowing unauthorized access to sensitive areas.