CVE-2025-46485
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 862
Summary
CVE-2025-46485 is a Missing Authorization vulnerability that affects the WP Customize Login Page, specifically versions from n/a to 1.6.5. This issue permits unauthorized access to functionality that is not adequately constrained by Access Control Lists (ACLs), potentially enabling attackers to bypass intended access restrictions. This could lead to significant security risks if exploited.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.