CVE-2025-49910: WordPress WPGuppy plugin <= 1.1.4 - Broken Access Control vulnerability
Published Oct 22, 2025
·Updated
Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPGuppy: from n/a through <= 1.1.4.
Affected Software
2 affected components
Amentotech WPGuppy<=1.1.4
WordPress WPGuppy<=1.1.4
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49910?
CVE-2025-49910 is classified as a Missing Authorization vulnerability that can lead to unauthorized access.
2
How do I fix CVE-2025-49910?
To fix CVE-2025-49910, upgrade WPGuppy to version 1.1.5 or later.
3
What software does CVE-2025-49910 affect?
CVE-2025-49910 affects AmentoTech WPGuppy versions up to and including 1.1.4.
4
What can happen if CVE-2025-49910 is exploited?
Exploitation of CVE-2025-49910 can allow attackers to access functionalities not properly constrained by access control lists (ACLs).
5
Is CVE-2025-49910 a common vulnerability?
CVE-2025-49910 is a specific vulnerability found in the WPGuppy plugin, affecting users who have not updated to the latest version.