CVE-2025-39456
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Apr 17, 2025
CWE ID 862
Summary
CVE-2025-39456 is a critical vulnerability affecting the iTRON WP Logger, which allows unauthorized access due to missing authorization checks. This issue stems from incorrectly configured access control security levels in the WP Logger software, from version 1 through 2.2. An attacker can exploit this vulnerability to gain unauthorized access to the system, potentially leading to data theft, manipulation, or system compromise. Users are advised to update their WP Logger software as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.