CVE-2025-64236: WordPress Tuturn plugin < 3.6 - Broken Authentication vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: from n/a before 3.6.
Other sources
Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn tuturn allows Authentication Abuse.This issue affects Tuturn: from n/a through < 3.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64236?
CVE-2025-64236 has a high severity rating due to its potential for enabling unauthorized access.
How do I fix CVE-2025-64236?
To fix CVE-2025-64236, upgrade AmentoTech Tuturn to version 3.6 or later to patch the vulnerability.
What impact does CVE-2025-64236 have on AmentoTech Tuturn?
CVE-2025-64236 allows for authentication bypass, leading to unauthorized actions within the application.
Is CVE-2025-64236 exploitable remotely?
Yes, CVE-2025-64236 is remotely exploitable, allowing attackers to bypass authentication without physical access.
Who is affected by CVE-2025-64236?
Users of AmentoTech Tuturn versions prior to 3.6 are affected by CVE-2025-64236.