CVE-2025-60128: WordPress Delisho Plugin <= 1.1.3 - Broken Access Control Vulnerability
Missing Authorization vulnerability in WP Delicious Delisho allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Delisho: from n/a through 1.1.3.
Other sources
Missing Authorization vulnerability in WP Delicious Delisho dr-widgets-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Delisho: from n/a through <= 1.1.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60128?
CVE-2025-60128 is classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-60128?
To fix CVE-2025-60128, update the WP Delicious Delisho to version 1.1.4 or later where the issue has been addressed.
What type of vulnerability is CVE-2025-60128?
CVE-2025-60128 is a missing authorization vulnerability that allows exploitation through incorrectly configured access control security levels.
Which versions of the WP Delicious Delisho are affected by CVE-2025-60128?
CVE-2025-60128 affects the WP Delicious Delisho versions up to and including 1.1.3.
What are the potential impacts of CVE-2025-60128?
The potential impacts of CVE-2025-60128 include unauthorized access to sensitive data and functionality within the affected plugin.