Description
Missing Authorization vulnerability in Wordapp Team Wordapp wordapp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wordapp: from n/a through <= 1.7.0.
Published: 2025-06-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Wordapp Team’s Wordapp plugin contains a missing authorization flaw that permits attackers to bypass normal access restrictions. The vulnerability is described as an incorrectly configured access control security level, which can enable unauthorized users to observe or manipulate data and functions that should be protected. This weakness is classified as CWE‑862, which means the software fails to enforce proper permissions for critical actions.

Affected Systems

The affected product is the Wordapp plugin for WordPress, distributed by the Wordapp Team. All installations of Wordapp from the first release up to and including version 1.7.0 are potentially vulnerable, as the issue exists in all releases up to that version, with no specific prior version that is excluded.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate impact severity. The EPSS score is reported as less than 1%, meaning the probability of exploitation is very low at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Attackers would likely need to access the WordPress administrative interface or otherwise interact with the plugin’s endpoints, so the attack vector is inferred to be web-based and requires a user to be authenticated or have some level of access to the site. The risk to an organization depends on whether the plugin is present, whether it is exposed to untrusted users, and how its settings are configured; nevertheless, patching is recommended to preclude potential misuse.

Generated by OpenCVE AI on April 30, 2026 at 18:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Wordapp to a version newer than 1.7.0
  • Verify that access control settings for the plugin are properly configured to restrict administrative functions to authorized users
  • Audit the WordPress permission structure to ensure that roles granted access to plugin features follow the principle of least privilege

Generated by OpenCVE AI on April 30, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17200 Missing Authorization vulnerability in Wordapp Team Wordapp allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wordapp: from n/a through 1.7.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Wordapp Team Wordapp allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wordapp: from n/a through 1.7.0. Missing Authorization vulnerability in Wordapp Team Wordapp wordapp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wordapp: from n/a through <= 1.7.0.
Title WordPress Wordapp <= 1.7.0 - Broken Access Control Vulnerability WordPress Wordapp plugin <= 1.7.0 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Fri, 06 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Wordapp Team Wordapp allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wordapp: from n/a through 1.7.0.
Title WordPress Wordapp <= 1.7.0 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:00.644Z

Reserved: 2025-03-26T09:21:51.872Z

Link: CVE-2025-30927

cve-icon Vulnrichment

Updated: 2025-06-06T15:04:15.442Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:33.227

Modified: 2026-04-23T15:27:20.530

Link: CVE-2025-30927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T18:30:16Z

Weaknesses