CVE-2025-1508

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 12, 2025
Updated: Mar 20, 2025
CWE ID 862

Summary

CVE-2025-1508 is a vulnerability affecting the WP Crowdfunding plugin for WordPress. The issue lies in the plugin's failure to implement proper capability checks for the 'download_data' action, which exists in all versions up to 2.1.13. Consequently, authenticated attackers with subscriber-level access and higher can exploit this flaw to gain unauthorized access to a site's post content, posing a significant risk when WooCommerce is installed.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Themeum Wp Crowdfunding

Affected Vendors

  • THEMEUM