CVE-2025-22770

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 27, 2025
CWE ID 862

Summary

CVE-2025-22770 is a new vulnerability affecting Envo Multipurpose, a multipurpose theme for WordPress. This issue involves a missing authorization control, which can be exploited by unauthorized users. The vulnerability allows attackers to bypass incorrectly configured access control security levels, potentially leading to unintended actions or data access. The theme versions from n/a to 1.1.6 are known to be affected by this vulnerability. It is crucial for users to update to the latest version or implement appropriate security measures to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share