Description
Missing Authorization vulnerability in paypalmuse PayPal Marketing Solutions paypal-promotions-and-insights allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through <= 1.2.
Published: 2025-01-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the PayPal Marketing Solutions WordPress plugin that permits unauthorized users to access or modify resources that should be protected. This flaw allows attackers with insufficient privileges to potentially view or alter plugin settings, potentially exposing sensitive advertising or payment data. The weakness is an example of improper authorization (CWE‑862) and results in a moderate impact on confidentiality and integrity.

Affected Systems

The affected product is the PayPal Marketing Solutions WordPress plugin developed by paypalmuse. All releases up to and including version 1.2 are impacted; the vulnerability exists in every version where the incorrect access control is present, regardless of release date. System administrators should verify the plugin version installed on each site and consider that any instance running a version ≤ 1.2 is susceptible.

Risk and Exploitability

The CVSS score of 4.3 reflects a moderate risk, and the EPSS score of <1 % indicates a very low likelihood that this flaw will be exploited in the wild at present. The vulnerability has not been listed in the CISA KEV catalog, further suggesting that it is not a known high‑profile exploit target. Attackers would likely need to target the web interface of a WordPress site that hosts the plugin and would exploit the mis‑configured authorization controls to read or change configuration data. Because the flaw is contained within the plugin, a successful exploit would be limited to the plugin’s functionality rather than the entire WordPress installation, but it still poses a risk to data that the plugin handles.

Generated by OpenCVE AI on May 1, 2026 at 20:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PayPal Marketing Solutions WordPress plugin to the latest available version (above 1.2). If a newer release is not yet provided, contact the plugin maintainer for an immediate fix.
  • Restrict administrative access to the plugin’s configuration pages by ensuring only users with the appropriate WordPress capabilities (such as administrator) can reach those endpoints.
  • If the PayPal Marketing Solutions plugin is not essential to your site’s operations, disable or uninstall it to remove the vulnerable code path.

Generated by OpenCVE AI on May 1, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3545 Missing Authorization vulnerability in iTechArt-Group PayPal Marketing Solutions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through 1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in iTechArt-Group PayPal Marketing Solutions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through 1.2. Missing Authorization vulnerability in paypalmuse PayPal Marketing Solutions paypal-promotions-and-insights allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through <= 1.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Fri, 17 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in iTechArt-Group PayPal Marketing Solutions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through 1.2.
Title WordPress PayPal Marketing Solutions plugin <= 1.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T22:39:45.280Z

Reserved: 2025-01-16T11:32:22.914Z

Link: CVE-2025-23930

cve-icon Vulnrichment

Updated: 2025-01-17T17:15:32.737Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:34.987

Modified: 2026-06-17T08:57:45.013

Link: CVE-2025-23930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T20:15:24Z

Weaknesses