CVE-2025-67919: WordPress Woffice Core plugin <= 5.4.30 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woffice Core: from n/a through <= 5.4.30.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67919?
CVE-2025-67919 is classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-67919?
To fix CVE-2025-67919, update Woffice Core to version 5.4.31 or later, which addresses the authorization bypass issue.
What systems are affected by CVE-2025-67919?
CVE-2025-67919 affects Woffice Core versions 5.4.30 and earlier.
What type of vulnerability is CVE-2025-67919?
CVE-2025-67919 is an authorization bypass vulnerability that allows exploitation through incorrectly configured access control levels.
Can CVE-2025-67919 lead to data breaches?
Yes, if exploited, CVE-2025-67919 can allow unauthorized access to sensitive user data, potentially leading to data breaches.