CVE-2025-62070: WordPress WowRevenue plugin <= 1.2.13 - Broken Access Control vulnerability
Published Oct 22, 2025
·Updated
Missing Authorization vulnerability in WPXPO WowRevenue revenue.This issue affects WowRevenue: from n/a through <= 1.2.13.
Affected Software
2 affected components
wpxpo WowRevenue<=1.2.13
WordPress WowRevenue<=1.2.13
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62070?
CVE-2025-62070 is classified as a medium severity vulnerability due to its impact on authorization controls.
2
How do I fix CVE-2025-62070?
To fix CVE-2025-62070, update the WowRevenue plugin to version 1.2.14 or later.
3
What is the impact of CVE-2025-62070?
CVE-2025-62070 can allow unauthorized users to access sensitive functionalities within the WowRevenue plugin.
4
Which versions are affected by CVE-2025-62070?
CVE-2025-62070 affects all versions of WowRevenue from n/a through 1.2.13.
5
Is CVE-2025-62070 a plugin vulnerability?
Yes, CVE-2025-62070 is a missing authorization vulnerability specifically in the WPXPO WowRevenue plugin.