CVE-2025-23514
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jan 16, 2025
CWE ID 862
Summary
CVE-2025-23514 is a critical vulnerability affecting Sanjaysolutions Loginplus, where access control lists (ACLs) do not properly constrain functionality. This issue enables unauthorized access to certain features in Loginplus versions 1.2 and below. An attacker can potentially bypass authorization checks and gain unauthorized access to restricted areas of the system, leading to potential data breaches or system compromise. Organizations using Loginplus are urged to apply the necessary patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress