Description
Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-Recall: from n/a through 16.26.14.
Published: 2025-06-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the WP‑Recall plugin that allows an attacker to invoke functions not properly protected by the plugin’s access control lists. Because the plugin fails to check user privileges before allowing certain operations, an attacker who successfully bypasses or authenticates to the plugin’s web endpoints could potentially perform actions that should be restricted, such as viewing or modifying sensitive data or configuration settings. This inference is based on the described lack of authorization checks.

Affected Systems

The affected product is the WP‑Recall plugin developed by tggfref. All released versions up to and including 16.26.14 are affected. WordPress sites that have installed this plugin and have not upgraded beyond that version remain vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score of < 1% suggests a low likelihood of exploitation in the wild at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The attack likely proceeds through the web interface of the plugin, requiring a user with access to the WordPress administrative pages. Since the flaw is a pure authorization bypass, it is inferred that any user who can access the plugin’s endpoints could exploit it unless further mitigated by role restrictions.

Generated by OpenCVE AI on May 2, 2026 at 01:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP‑Recall plugin to a version newer than 16.26.14 to apply the vendor fix.
  • If an upgrade is not immediately possible, restrict plugin access by removing user roles that are not required to use WP‑Recall functionality, limiting the potential attack surface.
  • Apply network or application firewall rules to block requests to WP‑Recall endpoints from unsanctioned IP addresses as a temporary containment measure.

Generated by OpenCVE AI on May 2, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28344 Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-Recall: from n/a through 16.26.14.
History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in tggfref WP-Recall wp-recall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP-Recall: from n/a through <= 16.26.14. Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-Recall: from n/a through 16.26.14.
References

Thu, 23 Apr 2026 15:45:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-Recall: from n/a through 16.26.14. Missing Authorization vulnerability in tggfref WP-Recall wp-recall allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP-Recall: from n/a through <= 16.26.14.
References

Mon, 23 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-Recall: from n/a through 16.26.14.
Title WordPress WP-Recall plugin <= 16.26.14 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:15.479Z

Reserved: 2025-06-11T16:07:56.073Z

Link: CVE-2025-49991

cve-icon Vulnrichment

Updated: 2025-06-23T17:15:43.724Z

cve-icon NVD

Status : Deferred

Published: 2025-06-20T15:15:25.320

Modified: 2026-04-28T19:33:18.270

Link: CVE-2025-49991

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T01:30:16Z

Weaknesses