Description
Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dashi: from n/a through <= 3.1.8.
Published: 2025-04-17
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from a missing authorization check in the jidaikobo Dashi WordPress plugin, which allows attackers to access privileged functionality that should be restricted by access control lists. The flaw enables an unauthenticated or low‑privilege user to trigger operations that could alter or disclose sensitive data, representing a moderate severity flaw classified as CWE‑862.

Affected Systems

The vulnerability affects the Dashi plugin distributed by jidaikobo. Any installation of Dashi version 3.1.8 or earlier is impacted, as the Access Control issue exists through the end of that version series.

Risk and Exploitability

With a CVSS score of 5.8, the flaw represents moderate risk. The EPSS score of < 1 % indicates a low probability that this vulnerability will be exploited in the wild. It is not listed in the CISA Known Exploited Vulnerabilities catalog, and no exploit code has been publicly disclosed. The likely attack vector is remote via the web interface, where an attacker can invoke the vulnerable plugin functions without proper authentication.

Generated by OpenCVE AI on April 30, 2026 at 22:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Dashi plugin to the latest available version (3.2.0 or later) to eliminate the access control flaw.
  • If an upgrade cannot be performed immediately, deactivate the plugin until a patched version is released to block unauthorized usage.
  • Apply role‑based restrictions to any Dashi admin pages using WordPress ACL plugins, limiting access to administrators only, as a temporary mitigation for the missing ACL enforcement.

Generated by OpenCVE AI on April 30, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11753 Missing Authorization vulnerability in jidaikobo Dashi allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dashi: from n/a through 3.1.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in jidaikobo Dashi allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dashi: from n/a through 3.1.8. Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dashi: from n/a through <= 3.1.8.
Title WordPress Dashi <= 3.1.8 - Broken Access Control Vulnerability WordPress Dashi plugin <= 3.1.8 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in jidaikobo Dashi allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dashi: from n/a through 3.1.8.
Title WordPress Dashi <= 3.1.8 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:35.077Z

Reserved: 2025-04-16T06:26:44.221Z

Link: CVE-2025-39580

cve-icon Vulnrichment

Updated: 2025-04-17T17:43:01.036Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:58.447

Modified: 2026-04-23T15:29:49.670

Link: CVE-2025-39580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:15:16Z

Weaknesses