Description
Missing Authorization vulnerability in javothemes Javo Core javo-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Javo Core: from n/a through <= 3.0.0.266.
Published: 2025-09-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Javo Core WordPress plugin. The flaw allows requests to bypass the plugin’s intended access controls, enabling users to view or manipulate data that should be restricted to authorized roles. The CVSS score of 5.3 places the issue in the moderate risk range, indicating that while it does not grant remote code execution, it permits exploitation of privileged actions within the plugin. The impact is limited to data exposure, unauthorized modification, and potential escalation of privileges within the boundaries of the plugin’s functionality.

Affected Systems

All installations of Javo Core from the earliest releases through version 3.0.0.266, used on WordPress‑powered websites. The affected component is the Java Themes Javo Core plugin, identified by the vendor/product pair javothemes:Javo Core.

Risk and Exploitability

The moderate CVSS score of 5.3 and an EPSS of less than 1% indicate a low likelihood of widespread real‑world exploitation. The flaw is not listed in the CISA KEV catalog, further supporting a low threat posture. The likely attack vector involves missing authentication checks on the plugin’s internal endpoints; the attacker must reach those endpoints, which may require some level of authenticated access or the ability to access the site’s public URLs that call the plugin’s functions. Because the vulnerability is fundamentally a broken access control, it depends on the plugin’s improper enforcement of role checks and is therefore exploitable only against sites that have the plugin installed and exposed to the web without proper protection.

Generated by OpenCVE AI on April 30, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a Javo Core version newer than 3.0.0.266, once it is available, to restore the missing authorization checks.
  • If an upgrade cannot be applied immediately, deactivate or delete the Javo Core plugin until a patch is released.
  • As a temporary measure, restrict the plugin’s administration and configuration pages by configuring role‑based capabilities so that only trusted administrators can access them.

Generated by OpenCVE AI on April 30, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30650 Missing Authorization vulnerability in javothemes Javo Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Javo Core: from n/a through 3.0.0.266.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in javothemes Javo Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Javo Core: from n/a through 3.0.0.266. Missing Authorization vulnerability in javothemes Javo Core javo-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Javo Core: from n/a through <= 3.0.0.266.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Javothemes
Javothemes javo Core
Wordpress
Wordpress wordpress
Vendors & Products Javothemes
Javothemes javo Core
Wordpress
Wordpress wordpress

Tue, 23 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in javothemes Javo Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Javo Core: from n/a through 3.0.0.266.
Title WordPress Javo Core Plugin <= 3.0.0.266 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Javothemes Javo Core
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:40.340Z

Reserved: 2025-08-22T11:37:32.967Z

Link: CVE-2025-58003

cve-icon Vulnrichment

Updated: 2025-09-23T13:57:45.814Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:01.543

Modified: 2026-04-23T15:33:13.017

Link: CVE-2025-58003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:15:06Z

Weaknesses