Description
Missing Authorization vulnerability in tsecher ts-tree ts-tree allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ts-tree: from n/a through <= 0.1.1.
Published: 2025-03-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the WordPress ts‑tree plugin enables an attacker to delete content arbitrarily. The weakness lies in incorrectly configured access control security levels, allowing the flaw to be exploited when a user has the ability to interact with the plugin’s functionality. While the description does not detail the exact trigger, the inferred attack vector is that an authenticated or remote user with sufficient privileges to invoke the plugin can execute delete operations on any content item. The consequence is the loss of legitimate content, potentially harming website integrity and business continuity.

Affected Systems

WordPress installations that include the ts‑tree plugin version 0.1.1 or earlier are impacted. This includes any site where the plugin is installed under the tsecher:ts-tree package, regardless of the WordPress version, as the flaw exists across all releases up to and including 0.1.1.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability, but the EPSS score of less than 1% suggests that exploit attempts in the wild are unlikely at present. Because this issue is not listed in the CISA KEV catalog, there is no known large‑scale exploitation campaign targeting it. Nonetheless, the risk lies primarily in the potential for data loss rather than in privilege escalation or external compromise. An attacker could achieve deletion without needing privileged system access, making the flaw attractive in scenarios where users have some level of access to the WordPress admin interface and the plugin’s features.

Generated by OpenCVE AI on May 1, 2026 at 14:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ts‑tree plugin to a version newer than 0.1.1 as soon as possible.
  • Verify that only users who require content management privileges have access to the plugin’s delete functions, and consider tightening role capabilities or using role‑based access control add‑ons to limit permissions.
  • If the plugin is not critical to site functionality, disable or uninstall it to eliminate the attack surface.
  • Monitor the site for unexpected deletions or activity logs that could indicate exploitation, and review audit trails regularly.

Generated by OpenCVE AI on May 1, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5734 Missing Authorization vulnerability in tsecher ts-tree allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ts-tree: from n/a through 0.1.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in tsecher ts-tree allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ts-tree: from n/a through 0.1.1. Missing Authorization vulnerability in tsecher ts-tree ts-tree allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ts-tree: from n/a through <= 0.1.1.
Title WordPress ts-tree plugin 0.1.1 - <= Arbitrary Content Deletion vulnerability WordPress ts-tree plugin <= 0.1.1 - Arbitrary Content Deletion vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Wed, 05 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in tsecher ts-tree allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ts-tree: from n/a through 0.1.1.
Title WordPress ts-tree plugin 0.1.1 - <= Arbitrary Content Deletion vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:11.872Z

Reserved: 2025-01-16T11:25:42.451Z

Link: CVE-2025-23515

cve-icon Vulnrichment

Updated: 2025-03-05T17:13:46.289Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:38.920

Modified: 2026-06-17T08:54:59.250

Link: CVE-2025-23515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T15:00:13Z

Weaknesses