CVE-2025-23906
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 17, 2025
CWE ID 862
Summary
CVE-2025-23906 represents a Missing Authorization vulnerability found in the WordPress Dashboard Tweeter plugin. This issue stems from incorrectly configured access control security levels, allowing unauthorized access to affected versions, ranging from n/a to 1.3.2. An attacker can exploit this vulnerability, potentially gaining unapproved entry into WordPress Dashboards and leading to further security breaches. It is crucial for users to promptly update their WordPress plugins to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.