CVE-2025-67972: WordPress Zoho ZeptoMail plugin <= 3.2.9 - Broken Access Control vulnerability
Published Feb 20, 2026
·Updated
Missing Authorization vulnerability in Zoho Mail Zoho ZeptoMail allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Zoho ZeptoMail: from n/a through 3.2.9.
Affected Software
1 affected component
Zoho Zoho ZeptoMail WordPress plugin<=3.2.9
Remediation
Information
Update the WordPress Zoho ZeptoMail Plugin to the latest available version (at least 3.3.0).
Event History
Feb 20, 2026
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-67972?
The severity of CVE-2025-67972 is medium with a CVSS score of 4.3.
2
What type of vulnerability is CVE-2025-67972?
CVE-2025-67972 is categorized as a Broken Access Control vulnerability.
3
How do I fix CVE-2025-67972?
To fix CVE-2025-67972, update the WordPress Zoho ZeptoMail plugin to version 3.3.0 or later.
4
What software is affected by CVE-2025-67972?
CVE-2025-67972 affects the Zoho ZoptoMail WordPress plugin versions from n/a to 3.2.9.
5
What impact does CVE-2025-67972 have on users?
CVE-2025-67972 can lead to exploitation due to incorrectly configured access control security levels.