CVE-2025-22302
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-22302 is a critical vulnerability affecting WP Wand version 1.2.5 and below. The issue stems from a missing authorization control, allowing unauthorized access to protected areas. Malicious actors can exploit this vulnerability by manipulating incorrectly configured access control security levels within WP Wand, putting sensitive data at risk. This weakness could lead to severe consequences, including unauthorized modification, disclosure, or deletion of information. System administrators are urged to update their WP Wand installations to the latest version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress