CVE-2025-68007: WordPress Event Espresso 4 Decaf plugin <= 5.0.37.decaf - Settings Change vulnerability
Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf event-espresso-decaf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Espresso 4 Decaf: from n/a through <= 5.0.37.decaf.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68007?
The severity of CVE-2025-68007 is critical as it involves a missing authorization vulnerability in the Event Espresso 4 Decaf plugin.
How do I fix CVE-2025-68007?
To fix CVE-2025-68007, update the Event Espresso 4 Decaf plugin to the latest version or at least version 5.0.38.
What types of access control issues does CVE-2025-68007 present?
CVE-2025-68007 presents incorrectly configured access control security levels that allow unauthorized changes to settings.
Is CVE-2025-68007 specific to a certain version of Event Espresso?
Yes, CVE-2025-68007 specifically affects Event Espresso 4 Decaf versions up to and including 5.0.37.decaf.
Can CVE-2025-68007 lead to unauthorized actions in WordPress?
Yes, CVE-2025-68007 can lead to unauthorized actions in WordPress due to the lack of proper authorization checks.