CVE-2025-60143: WordPress Netgsm plugin <= 2.9.70 - Broken Access Control vulnerability
Missing Authorization vulnerability in netgsm Netgsm allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Netgsm: from n/a through 2.9.58.
Other sources
Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netgsm: from n/a through <= 2.9.70.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60143?
CVE-2025-60143 is classified as a missing authorization vulnerability that can lead to unauthorized access to sensitive functionalities.
How do I fix CVE-2025-60143?
To fix CVE-2025-60143, ensure proper configuration of access control security levels in Netgsm and update to the latest version beyond 2.9.58.
What software is affected by CVE-2025-60143?
CVE-2025-60143 affects Netgsm versions from n/a through 2.9.58, including the Netgsm WordPress plugin up to version 2.9.58.
What impact does CVE-2025-60143 have?
Exploiting CVE-2025-60143 can allow attackers to bypass authorization checks, potentially leading to unauthorized actions on the system.
Is there a patch available for CVE-2025-60143?
Yes, users should apply the latest updates from Netgsm to resolve the vulnerabilities associated with CVE-2025-60143.