CVE-2025-61654: UserInfoCard: Do permission checking when getting counts of global and local edits, new articles and thanks
Published Feb 3, 2026
·Updated
Vulnerability in Wikimedia Foundation Thanks. This vulnerability is associated with program files includes/ThanksQueryHelper.Php.
This issue affects Thanks: from before 1.43.4, 1.44.1.
Affected Software
1 affected component
Wikimedia Foundation Thanks<1.43.4
Event History
Feb 3, 2026
CVE Published
via MITRE·01:08 AM
Data Sourced
via MITRE·01:08 AM
Description
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-61654?
CVE-2025-61654 has a medium severity level due to improper permission checks.
2
How do I fix CVE-2025-61654?
To fix CVE-2025-61654, upgrade the Wikimedia Foundation Thanks software to version 1.43.4 or later.
3
What software is affected by CVE-2025-61654?
CVE-2025-61654 affects Wikimedia Foundation Thanks versions prior to 1.43.4 and 1.44.1.
4
What types of issues are associated with CVE-2025-61654?
CVE-2025-61654 is linked to improper permission checking related to user permissions for edit counts and article creation.
5
Who is responsible for addressing CVE-2025-61654?
The Wikimedia Foundation is responsible for addressing and mitigating the vulnerabilities associated with CVE-2025-61654.