CVE-2025-62893: WordPress Create by Mediavine plugin <= 1.9.14 - Insecure Direct Object References (IDOR) vulnerability
Published Oct 27, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
Mediavine Create by Mediavine<=1.9.14
Event History
Oct 27, 2025
CVE Published
via MITRE·01:33 AM
Rejected
via MITRE·01:33 AM
Data Sourced
via NVD·02:15 AM
Description
Dec 8, 2025
Rejected
via MITRE·03:37 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-62893?
CVE-2025-62893 is classified as a high severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2025-62893?
To fix CVE-2025-62893, update the Create by Mediavine plugin to version 1.9.15 or higher.
3
What systems are affected by CVE-2025-62893?
CVE-2025-62893 affects all versions of Create by Mediavine up to and including 1.9.14.
4
What type of vulnerability is CVE-2025-62893?
CVE-2025-62893 is an Authorization Bypass vulnerability, allowing exploitation of incorrectly configured access controls.
5
Who should be concerned about CVE-2025-62893?
All users utilizing Create by Mediavine versions 1.9.14 and below should be concerned about CVE-2025-62893.