CVE-2025-57975: WordPress Team Plugin <= 5.0.6 - Broken Access Control Vulnerability
Missing Authorization vulnerability in RadiusTheme Team allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Team: from n/a through 5.0.6.
Other sources
Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57975?
CVE-2025-57975 has a critical severity due to the potential exploitation of missing authorization in access control configurations.
How do I fix CVE-2025-57975?
To fix CVE-2025-57975, update RadiusTheme Team or WordPress Team Plugin to version 5.0.7 or later, where the vulnerability is patched.
Who is affected by CVE-2025-57975?
CVE-2025-57975 affects users running RadiusTheme Team and WordPress Team Plugin versions up to and including 5.0.6.
What is the nature of the vulnerability in CVE-2025-57975?
CVE-2025-57975 is a missing authorization vulnerability that allows unauthorized access due to incorrectly configured security levels.
Can CVE-2025-57975 be exploited remotely?
Yes, CVE-2025-57975 can be exploited remotely by attackers to gain unauthorized access to restricted functionalities.