CVE-2025-22736

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 15, 2025
CWE ID 266

Summary

CVE-2025-22736 is an Incorrect Privilege Assignment vulnerability affecting WPExperts User Management, specifically versions from 1.2. This issue grants Privilege Escalation to attackers, allowing them to elevate their access levels and gain unauthorized control beyond their intended permissions. This vulnerability could potentially result in significant security risks and potential data breaches for websites utilizing the impacted version of WPExperts User Management. It is crucial for users to update to the latest, secure version of the plugin as soon as possible to mitigate these risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • User Management Plugin

Affected Vendors

  • WordPress