CVE-2025-23929

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 16, 2025
CWE ID 862

Summary

CVE-2025-23929 is a critical vulnerability affecting the Email Capture & Lead Generation plugin between versions n/a and 1.0.2. This issue involves a Missing Authorization flaw, which enables unauthorized access and potential exploitation. The vulnerability stems from incorrectly configured access control security levels, allowing attackers to gain unauthorized access to sensitive information or functions within the plugin. This poses a significant risk to users, who are advised to update to the latest version or apply patches as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share