CVE-2025-32225

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 862

Summary

CVE-2025-32225 is a Missing Authorization vulnerability affecting the WP Event Manager plugin. This issue permits unauthorized access, exploiting incorrectly configured access control security levels within the plugin. The vulnerability affects WP Event Manager versions from n/a through 3.1.47. Successful exploitation could potentially lead to unintended alteration or deletion of data, and even complete takeover of the affected WordPress site. It is essential for users to update their WP Event Manager plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share