CVE-2025-49906: WordPress WPComplete plugin <= 2.9.5.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in StellarWP WPComplete wpcomplete allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPComplete: from n/a through <= 2.9.5.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49906?
CVE-2025-49906 is classified as a missing authorization vulnerability that allows access to functionalities not properly constrained by Access Control Lists (ACLs).
How do I fix CVE-2025-49906?
To fix CVE-2025-49906, update StellarWP WPComplete to version 2.9.5.4 or later to ensure proper access controls are enforced.
Which versions of WPComplete are affected by CVE-2025-49906?
CVE-2025-49906 affects all versions of WPComplete from n/a through version 2.9.5.3.
What are the potential risks of CVE-2025-49906?
The risks associated with CVE-2025-49906 include unauthorized access to sensitive functionalities, which could lead to data breaches or malicious activities on the site.
Is CVE-2025-49906 publicly known?
Yes, CVE-2025-49906 is a publicly known vulnerability and should be addressed promptly to mitigate potential risks.