CVE-2025-31846
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 1, 2025
CWE ID 862
Summary
CVE-2025-31846 is a new vulnerability affecting the Theater for WordPress plugin. This missing authorization issue enables unauthorized access, allowing exploitation of incorrectly configured security levels. The plugin, which is used for managing theater schedules and bookings, is impacted from its non-available version through 0.18.7. Successful exploitation could lead to significant security risks, underscoring the importance of updating to the latest secure plugin version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress