CVE-2025-67560: WordPress Listdom plugin <= 5.0.1 - Broken Access Control vulnerability
Published Dec 9, 2025
·Updated
Missing Authorization vulnerability in Webilia Inc. Listdom listdom allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Listdom: from n/a through <= 5.0.1.
Affected Software
2 affected components
Webilia Listdom<=5.0.1
wordpress/listdom<=5.0.1
Event History
Dec 9, 2025
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Nov 30, 58290
Event
via MITRE·08:37 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-67560?
CVE-2025-67560 is classified as a high severity vulnerability due to its potential impact on access control.
2
How do I fix CVE-2025-67560?
To fix CVE-2025-67560, upgrade the Listdom plugin to version 5.0.2 or later.
3
What types of attacks can CVE-2025-67560 enable?
CVE-2025-67560 can allow unauthorized users to gain access to restricted functionalities or sensitive data.
4
Who is affected by CVE-2025-67560?
CVE-2025-67560 affects users of the Webilia Listdom plugin versions 5.0.1 and earlier.
5
Is CVE-2025-67560 a remote code execution vulnerability?
No, CVE-2025-67560 is a Broken Access Control vulnerability, not a remote code execution vulnerability.