Description
Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager wp-sri allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subresource Integrity (SRI) Manager: from n/a through <= 0.4.0.
Published: 2025-09-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Meitar’s Subresource Integrity (SRI) Manager plugin fails to enforce proper authorization checks, enabling an attacker to bypass the intended security boundaries of the plugin. Because the vulnerability allows exploitation of incorrectly configured access control security levels, an attacker could read or manipulate configuration settings and other protected content that should be restricted. The weakness is recorded as CWE‑862 and is limited to unauthorized access, not impacting code execution or availability directly.

Affected Systems

The affected product is the WordPress Subresource Integrity (SRI) Manager plugin from Meitar. Versions from the earliest available release up through 0.4.0 inclusive are vulnerable. Users running the plugin on any WordPress installation are at risk if they have not applied a corrective update.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of real‑world exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and there are no public exploits described in the available references. The attack vector is inferred to be possible for anyone able to access the WordPress admin interface or otherwise interact with the plugin’s endpoints, provided the access control weaknesses are active. Upgrading to a fixed version would eliminate the risk.

Generated by OpenCVE AI on April 30, 2026 at 00:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Subresource Integrity (SRI) Manager plugin to a version newer than 0.4.0, which contains the access control fix.
  • Verify that the plugin’s configuration is aligned with the principle that only authorized users can modify SRI settings, and enforce role‑based restrictions accordingly.
  • If an update is not immediately possible, disable or remove the plugin from the WordPress installation until a patch is applied, to prevent the exploitation of the broken authorization checks.

Generated by OpenCVE AI on April 30, 2026 at 00:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30691 Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Subresource Integrity (SRI) Manager: from n/a through 0.4.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Subresource Integrity (SRI) Manager: from n/a through 0.4.0. Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager wp-sri allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subresource Integrity (SRI) Manager: from n/a through <= 0.4.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 23 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Meitar
Meitar subresource Integrity Manager
Wordpress
Wordpress wordpress
Vendors & Products Meitar
Meitar subresource Integrity Manager
Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Subresource Integrity (SRI) Manager: from n/a through 0.4.0.
Title WordPress Subresource Integrity (SRI) Manager Plugin <= 0.4.0 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Meitar Subresource Integrity Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:38.986Z

Reserved: 2025-08-22T11:36:33.371Z

Link: CVE-2025-57936

cve-icon Vulnrichment

Updated: 2025-09-23T15:40:15.640Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:15:51.070

Modified: 2026-04-23T15:33:04.543

Link: CVE-2025-57936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T01:00:13Z

Weaknesses