CVE-2025-49903: WordPress ZoloBlocks plugin <= 2.3.11 - Broken Access Control vulnerability
Missing Authorization vulnerability in bdthemes ZoloBlocks zoloblocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ZoloBlocks: from n/a through <= 2.3.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49903?
CVE-2025-49903 is classified as a missing authorization vulnerability, which can lead to unauthorized access due to incorrectly configured access control settings.
How do I fix CVE-2025-49903?
To fix CVE-2025-49903, upgrade the ZoloBlocks plugin to the latest version beyond 2.3.11, where the vulnerability has been addressed.
Which versions of ZoloBlocks are affected by CVE-2025-49903?
CVE-2025-49903 affects ZoloBlocks versions from the beginning up to and including 2.3.11.
Can CVE-2025-49903 be exploited by attackers?
Yes, CVE-2025-49903 can be exploited by attackers to gain unauthorized access, making it a significant security risk.
What type of vulnerability is CVE-2025-49903?
CVE-2025-49903 is a broken access control vulnerability that results from missing authorization checks.