Description
Missing Authorization vulnerability in publitio Publitio publitio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Publitio: from n/a through <= 2.1.8.
Published: 2025-04-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Publitio WordPress plugin that allows attackers to bypass access controls and perform actions reserved for higher‑privileged users. This breach of access controls can lead to unauthorized data exposure or manipulation within the WordPress site, compromising the confidentiality and integrity of site content and user data. The weakness is identified as CWE‑862 (Broken Access Control).

Affected Systems

The affected software is the Publitio plugin for WordPress (publitio:Publitio). All installations running version 2.1.8 or earlier are vulnerable; the plugin versions prior to 2.1.8 have not been patched.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk, while the EPSS score of less than 1% suggests the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog, further indicating it is not a high‑profile exploit. The attack vector is inferred to be remote via the web interface, as the flaw exists within a WordPress plugin that is exposed to authenticated or unauthenticated users, depending on the site’s configuration.

Generated by OpenCVE AI on May 1, 2026 at 02:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Publitio plugin to version 2.1.9 or later to apply the vendor’s fix for the broken access control flaw.
  • If an immediate update is not feasible, disable the Publitio plugin or restrict its activation to administrative users only to prevent potential misuse.
  • Review and enforce strict role‑based access controls for WordPress users, ensuring that only authorized accounts can interact with the Publitio plugin and that plugin permissions are no broader than necessary.

Generated by OpenCVE AI on May 1, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9239 Missing Authorization vulnerability in publitio Publitio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Publitio: from n/a through 2.1.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in publitio Publitio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Publitio: from n/a through 2.1.8. Missing Authorization vulnerability in publitio Publitio publitio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Publitio: from n/a through <= 2.1.8.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 02 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in publitio Publitio allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Publitio: from n/a through 2.1.8.
Title WordPress Publitio Plugin <= 2.1.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.876Z

Reserved: 2025-04-01T13:20:05.025Z

Link: CVE-2025-31798

cve-icon Vulnrichment

Updated: 2025-04-02T15:18:04.694Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:18.893

Modified: 2026-04-23T15:28:18.960

Link: CVE-2025-31798

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:15:06Z

Weaknesses