CVE-2025-6813: aapanel WP Toolkit 1.0 - 1.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via auto_login() Function
The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the autologin() function in versions 1.0 to 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass all role checks and gain full admin privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
aapanel WP Toolkitto a version that resolves this vulnerability.Fixed in 1.0 to 1.1Patch aapanel WP Toolkit 1.0 - 1.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via auto_login() Function
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6813?
CVE-2025-6813 has a medium severity rating due to its potential for privilege escalation.
How do I fix CVE-2025-6813?
To fix CVE-2025-6813, update the aapanel WP Toolkit plugin to version 1.2 or later.
Who is affected by CVE-2025-6813?
CV-2025-6813 affects authenticated users with Subscriber-level access and above on WordPress sites using the vulnerable plugin versions.
What does the CVE-2025-6813 vulnerability allow attackers to do?
CVE-2025-6813 allows attackers to bypass authorization checks and escalate their privileges within the WordPress site.
What versions of the aapanel WP Toolkit are vulnerable to CVE-2025-6813?
Versions 1.0 to 1.1 of the aapanel WP Toolkit plugin are vulnerable to CVE-2025-6813.