CVE-2025-24643

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 3, 2025
CWE ID 862

Summary

CVE-2025-24643 is a security vulnerability affecting Amento Tech Pvt ltd's WPGuppy plugin. This issue involves missing authorization, permitting unauthorized access to functions. The vulnerability can be exploited if access control security levels are incorrectly configured. The WPGuppy plugin, which is used by an unknown number of sites, is impacted from its inception through version 1.1.0. It is crucial for users to update their plugins to mitigate this risk and maintain a secure digital environment.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share