CVE-2025-60106: WordPress EmailKit Plugin <= 1.6.0 - Arbitrary Content Deletion Vulnerability
Missing Authorization vulnerability in Roxnor EmailKit allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EmailKit: from n/a through 1.6.0.
Other sources
Missing Authorization vulnerability in Roxnor EmailKit emailkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmailKit: from n/a through <= 1.6.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60106?
CVE-2025-60106 has a high severity due to its exploitation potential related to missing authorization and incorrect access control.
How do I fix CVE-2025-60106?
To fix CVE-2025-60106, upgrade Roxnor EmailKit and WordPress EmailKit Plugin to version 1.6.1 or later.
What versions are affected by CVE-2025-60106?
CVE-2025-60106 affects Roxnor EmailKit and WordPress EmailKit Plugin versions up to and including 1.6.0.
What type of vulnerability is CVE-2025-60106?
CVE-2025-60106 is a Missing Authorization vulnerability allowing unauthorized access due to misconfigured security levels.
Can CVE-2025-60106 be exploited remotely?
Yes, CVE-2025-60106 can be exploited remotely by an attacker if the affected software is improperly configured.