Description
Missing Authorization vulnerability in WPManiax WP DB Booster wp-db-booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP DB Booster: from n/a through <= 1.0.1.
Published: 2025-06-27
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw (CWE‑862) that allows an attacker to bypass the normal access controls within the WP DB Booster plugin. This flaw can enable the attacker to view, modify or delete WordPress database tables, and change administrative settings. The potential impact includes compromise of confidentiality, integrity and availability of the site’s data, and could provide a foothold for further attacks.

Affected Systems

The plugin vendor is WPManiax and the affected product is WP DB Booster for WordPress. Any installation of the plugin with version 1.0.1 or earlier is vulnerable, regardless of the WordPress core version. Sites that rely on the plugin for database optimization should be considered at risk. The vulnerability affects instances where the plugin is installed and accessible through the WordPress administration interface.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is less than 1%, suggesting a low probability of exploitation based on current threat intelligence and the fact that the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web interface; an attacker would need access to the site or an entry point that triggers the plugin’s admin endpoints. If exploited, privilege escalation within the site’s administration can lead to full control over the underlying database, enabling data theft, site defacement, or persistence. The overall risk depends on the exposure of the WordPress installation and whether administrators are at risk.

Generated by OpenCVE AI on April 30, 2026 at 17:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP DB Booster to version 1.0.2 or later from WPManiax.
  • Restrict or remove user roles that have access to the plugin’s administrative interface.
  • Review all WordPress user roles and permissions to ensure no unnecessary privileges are granted.
  • Audit other installed plugins for similar access control weaknesses.

Generated by OpenCVE AI on April 30, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19369 Missing Authorization vulnerability in WPManiax WP DB Booster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP DB Booster: from n/a through 1.0.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WPManiax WP DB Booster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP DB Booster: from n/a through 1.0.1. Missing Authorization vulnerability in WPManiax WP DB Booster wp-db-booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP DB Booster: from n/a through <= 1.0.1.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}


Fri, 27 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 13:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WPManiax WP DB Booster allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP DB Booster: from n/a through 1.0.1.
Title WordPress WP DB Booster plugin <= 1.0.1 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:23.610Z

Reserved: 2025-06-27T11:59:14.509Z

Link: CVE-2025-53318

cve-icon Vulnrichment

Updated: 2025-06-27T13:45:52.463Z

cve-icon NVD

Status : Deferred

Published: 2025-06-27T14:15:54.410

Modified: 2026-04-23T15:32:29.157

Link: CVE-2025-53318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T17:15:42Z

Weaknesses