CVE-2025-22298

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 7, 2025
CWE ID 862

Summary

CVE-2025-22298 is a Missing Authorization vulnerability affecting Hive Support – WordPress Help Desk, versions up to 1.1.6. This issue stems from incorrectly configured access control security levels, allowing unauthorized access and potential exploitation. The flaw enables attackers to gain unapproved access to sensitive data or functionality, posing a significant risk to affected WordPress installations. System administrators are urged to upgrade to a patched version of Hive Support as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share