CVE-2025-50010: WordPress Zapier for WordPress plugin <= 1.5.2 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Zapier Zapier for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zapier for WordPress: from n/a through 1.5.2.
Other sources
Missing Authorization vulnerability in Zapier Zapier for WordPress zapier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zapier for WordPress: from n/a through <= 1.5.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50010?
The severity of CVE-2025-50010 is classified as a critical vulnerability due to its impact on access controls.
How do I fix CVE-2025-50010?
To fix CVE-2025-50010, update Zapier for WordPress to version 1.5.3 or later.
What impact does CVE-2025-50010 have on my site?
CVE-2025-50010 can lead to unauthorized access to restricted areas of your WordPress site if not mitigated.
Is CVE-2025-50010 specific to certain versions of Zapier for WordPress?
Yes, CVE-2025-50010 affects Zapier for WordPress versions up to and including 1.5.2.
What should I do if I cannot update Zapier for WordPress to mitigate CVE-2025-50010?
If unable to update, consider disabling the plugin temporarily and reviewing access controls to reduce risks associated with CVE-2025-50010.