Description
Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Loops WP Integration: from n/a through <= 3.8.1.
Published: 2025-06-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Viral Loops WP Integration plugin that allows an attacker to exploit incorrectly configured access controls. By manipulating request parameters or accessing specific plugin endpoints, a threat actor can gain access to administrative functions or sensitive settings that should be restricted only to privileged users. The impact is elevation of privileges and potential unauthorized configuration changes, which could compromise site data or further enable other attacks.

Affected Systems

Affected systems are WordPress sites running the Viral Loops WP Integration plugin version 3.8.1 or earlier. The plugin is published by Viralloops and is listed under the vendor name Viral Loops WP Integration. The vulnerability applies to all installations from the initial release through version 3.8.1; later versions have not been identified as affected by this flaw.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate severity for missing authorization, while the EPSS score of less than 1% suggests that this vulnerability is unlikely to be actively exploited in the wild at this time. The vulnerability is not included in the CISA KEV catalog, further implying a lower exploitation risk. The likely attack vector is through web-based access to the plugin’s administrative endpoints, possibly requiring an authenticated user with limited rights or simply an unauthenticated user if certain endpoints are exposed. Without a public exploit, the risk remains moderate until the patch is applied.

Generated by OpenCVE AI on April 30, 2026 at 18:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Viral Loops WP Integration plugin to any version newer than 3.8.1, which removes the missing authorization flaw.
  • If an update is not immediately available, deactivate or uninstall the plugin to eliminate the attack surface.
  • Configure WordPress or your security plugin to restrict access to the plugin’s administrative endpoints to administrator roles only, adding an extra layer of access control.

Generated by OpenCVE AI on April 30, 2026 at 18:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17180 Missing Authorization vulnerability in viralloops Viral Loops WP Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Viral Loops WP Integration: from n/a through 3.8.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in viralloops Viral Loops WP Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Viral Loops WP Integration: from n/a through 3.8.1. Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Loops WP Integration: from n/a through <= 3.8.1.
Title WordPress Viral Loops WP Integration <= 3.8.1 - Broken Access Control Vulnerability WordPress Viral Loops WP Integration plugin <= 3.8.1 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Fri, 06 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in viralloops Viral Loops WP Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Viral Loops WP Integration: from n/a through 3.8.1.
Title WordPress Viral Loops WP Integration <= 3.8.1 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:52.480Z

Reserved: 2025-03-11T08:10:52.910Z

Link: CVE-2025-28995

cve-icon Vulnrichment

Updated: 2025-06-06T14:58:05.503Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:29.943

Modified: 2026-04-23T15:26:45.097

Link: CVE-2025-28995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T18:15:06Z

Weaknesses