Description
The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the annfu_reset_options() function in all versions up to, and including, 4.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all 29 plugin options, effectively resetting the plugin to its default state.
Published: 2025-12-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized deletion of plugin options by users with Subscriber level access or higher
Action: Patch Immediately
AI Analysis

Impact

A missing capability check in the annfu_reset_options() function of the AnnunciFunebri Impresa WordPress plugin allows an authenticated user with Subscriber or higher privileges to delete all 29 plugin options, resetting the plugin to its default state. This loss of configuration can disrupt funeral announcement services and affect the integrity of site data.

Affected Systems

The vulnerability is present in all releases of the AnnunciFunebri plugin up to and including version 4.7.0. WordPress sites that install any of these versions and grant Subscriber or greater roles to users are affected.

Risk and Exploitability

The CVSS score is 4.3 and the EPSS score is below 1%, indicating a low to moderate severity and a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Because exploitation requires a valid WordPress account with Subscriber or higher privileges, the threat primarily comes from compromised or malicious internal accounts rather than external attackers.

Generated by OpenCVE AI on April 22, 2026 at 16:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the AnnunciFunebri plugin to a version that includes the missing capability check.
  • If an update is not immediately possible, remove or restrict the annfu_reset_options capability from the Subscriber role, or disable the plugin until a fix is available.
  • As a temporary workaround, manually recreate the plugin options and limit access to the reset functionality by adjusting user role permissions.

Generated by OpenCVE AI on April 22, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 17:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Mon, 15 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 14 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Sat, 13 Dec 2025 04:45:00 +0000

Type Values Removed Values Added
Description The AnnunciFunebri Impresa plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the annfu_reset_options() function in all versions up to, and including, 4.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all 29 plugin options, effectively resetting the plugin to its default state.
Title AnnunciFunebri Impresa <= 4.7.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Deletion
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:43:42.875Z

Reserved: 2025-12-10T13:54:13.521Z

Link: CVE-2025-14447

cve-icon Vulnrichment

Updated: 2025-12-15T15:25:11.847Z

cve-icon NVD

Status : Deferred

Published: 2025-12-13T16:16:49.860

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T16:15:21Z

Weaknesses