CVE-2025-58680: WordPress Gutentor plugin <= 3.5.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in gutentor Gutentor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutentor: from n/a through 3.5.2.
Other sources
Missing Authorization vulnerability in gutentor Gutentor gutentor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutentor: from n/a through <= 3.5.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58680?
CVE-2025-58680 has been classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-58680?
To fix CVE-2025-58680, upgrade Gutentor to version 3.5.3 or later to ensure proper access control configurations.
What systems are affected by CVE-2025-58680?
CVE-2025-58680 affects all versions of Gutentor up to and including 3.5.2.
What attack vectors exist for CVE-2025-58680?
Attackers can exploit CVE-2025-58680 through incorrectly configured access control levels within the Gutentor plugin.
Is there a workaround for CVE-2025-58680 if I cannot update immediately?
A temporary workaround for CVE-2025-58680 may involve manually auditing user permissions and restricting access as much as possible until an update is applied.