Description
Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Agency Toolkit: from n/a through <= 1.0.24.
Published: 2025-04-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the Agency Toolkit plugin allows attackers with lower privileges to access or modify protected resources, potentially leading to unauthorized data disclosure or modification. The weakness is a missing authorization check, identified as CWE‑862.

Affected Systems

The WordPress Agency Toolkit plugin (inspry:Agency Toolkit) from the earliest documented release through 1.0.24 is affected. WordPress sites running these versions are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% signals a very low likelihood of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation could involve an attacker with some level of authentication who submits requests to the plugin’s API or webpages that bypass the intended access controls, allowing unauthorized data access or modification.

Generated by OpenCVE AI on May 1, 2026 at 11:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Agency Toolkit plugin to a version newer than 1.0.24
  • If an upgrade is not immediately possible, restrict the plugin’s administrative pages to administrators only, ensuring that no lower‑privileged users can access them
  • Disable or remove the Agency Toolkit plugin if it is not required for site functionality, to eliminate the vulnerable code path

Generated by OpenCVE AI on May 1, 2026 at 11:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9167 Missing Authorization vulnerability in inspry Agency Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Agency Toolkit: from n/a through 1.0.23.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in inspry Agency Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Agency Toolkit: from n/a through 1.0.23. Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Agency Toolkit: from n/a through <= 1.0.24.
Title WordPress Agency Toolkit plugin <= 1.0.23 - Broken Access Control vulnerability WordPress Agency Toolkit plugin <= 1.0.24 - Broken Access Control vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 01 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in inspry Agency Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Agency Toolkit: from n/a through 1.0.23.
Title WordPress Agency Toolkit plugin <= 1.0.23 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:14.724Z

Reserved: 2025-04-01T13:21:07.842Z

Link: CVE-2025-31863

cve-icon Vulnrichment

Updated: 2025-04-01T16:00:39.777Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:28.257

Modified: 2026-04-23T15:28:26.597

Link: CVE-2025-31863

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:45:16Z

Weaknesses