CVE-2025-66532: WordPress Powerlift theme < 3.2.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Mikado-Themes Powerlift powerlift allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Powerlift: from n/a through < 3.2.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66532?
CVE-2025-66532 is considered a medium-severity vulnerability due to missing authorization in access control settings.
How do I fix CVE-2025-66532?
To fix CVE-2025-66532, update your Mikado-Themes Powerlift to version 3.2.1 or later, which addresses the access control issues.
What type of vulnerability is CVE-2025-66532?
CVE-2025-66532 is a Missing Authorization vulnerability that allows unauthorized access due to incorrect security configurations.
Which versions of Powerlift are affected by CVE-2025-66532?
CVE-2025-66532 affects all versions of Mikado-Themes Powerlift prior to 3.2.1.
What impact does CVE-2025-66532 have on users?
The impact of CVE-2025-66532 can lead to unauthorized access to restricted areas of the Powerlift theme, potentially compromising user data.