CVE-2025-60165: WordPress Frames Theme <= 1.5.7 - Broken Access Control Vulnerability
Missing Authorization vulnerability in HaruTheme Frames allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Frames: from n/a through 1.5.7.
Other sources
Missing Authorization vulnerability in HaruTheme Frames frames allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frames: from n/a through <= 1.5.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60165?
The severity of CVE-2025-60165 is rated as critical due to missing authorization that can lead to unauthorized access.
How do I fix CVE-2025-60165?
To fix CVE-2025-60165, update HaruTheme Frames to the latest version that addresses the missing authorization vulnerability.
Which versions of HaruTheme Frames are affected by CVE-2025-60165?
CVE-2025-60165 affects all versions of HaruTheme Frames from n/a to 1.5.7.
Can CVE-2025-60165 affect WordPress installations?
Yes, CVE-2025-60165 also affects the WordPress Frames Theme up to version 1.5.7.
What type of vulnerability is CVE-2025-60165?
CVE-2025-60165 is classified as a missing authorization vulnerability related to incorrectly configured access control security levels.