CVE-2025-23916

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 16, 2025
CWE ID 862

Summary

CVE-2025-23916 is a missing authorization vulnerability affecting WP Meetup, a plugin used in WordPress websites. This issue arises due to inadequately configured access control security levels. An attacker can exploit this vulnerability to gain unauthorized access, affecting WP Meetup versions from n/a to 2.3.0. Site administrators are advised to update the plugin to the latest version and review their access control settings to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share