CVE-2025-46485

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 862

Summary

CVE-2025-46485 is a Missing Authorization vulnerability that affects the WP Customize Login Page, specifically versions from n/a to 1.6.5. This issue permits unauthorized access to functionality that is not adequately constrained by Access Control Lists (ACLs), potentially enabling attackers to bypass intended access restrictions. This could lead to significant security risks if exploited.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share