CVE-2025-59561: WordPress Smart Blocks Plugin <= 2.4 - Broken Access Control Vulnerability
Missing Authorization vulnerability in hashthemes Smart Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Blocks: from n/a through 2.4.
Other sources
Missing Authorization vulnerability in hashthemes Smart Blocks smart-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Blocks: from n/a through <= 2.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59561?
CVE-2025-59561 is classified as a critical vulnerability due to its potential to allow unauthorized access and exploitation.
How do I fix CVE-2025-59561?
To fix CVE-2025-59561, update the HashThemes Smart Blocks or WordPress Smart Blocks Plugin to version 2.5 or higher.
Who is affected by CVE-2025-59561?
CVE-2025-59561 affects users of HashThemes Smart Blocks and WordPress Smart Blocks Plugin versions up to and including 2.4.
What type of vulnerability is CVE-2025-59561?
CVE-2025-59561 is a missing authorization vulnerability that can lead to insecure access control.
What can an attacker do with CVE-2025-59561?
An attacker exploiting CVE-2025-59561 could gain unauthorized access to sensitive information and potentially alter site content.