Description
Missing Authorization vulnerability in yydevelopment Mobile Contact Line mobile-contact-line allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile Contact Line: from n/a through <= 2.4.0.
Published: 2025-09-03
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the yydevelopment Mobile Contact Line plugin is a missing authorization flaw that allows users to access or manipulate functionality intended for privileged users. This flaw arises from incorrectly configured access control security levels, which can enable attackers to read or modify plugin settings or trigger actions that should be restricted. Consequently, data confidentiality and integrity may be compromised, potentially exposing sensitive contact information or allowing the insertion of inappropriate content.

Affected Systems

The vulnerability impacts the Mobile Contact Line plugin distributed by yydevelopment. All released versions up through and including 2.4.0 are affected; no specific sub‑packages are mentioned and the issue spans the entire plugin codebase.

Risk and Exploitability

The CVSS base score of 4.3 indicates a moderate impact if exploited, while the EPSS score of <1% suggests that widespread exploitation is unlikely. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves the plugin’s administrative interface or exposed API endpoints, where an attacker could craft requests to reach protected functions without appropriate permission checks. The description does not specify whether an unauthenticated or a privileged user is required, so the exact risk depends on the system’s current role configuration.

Generated by OpenCVE AI on April 30, 2026 at 02:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Mobile Contact Line plugin to a version that fixes the access control weakness, such as 2.4.1 or newer.
  • If an update is not immediately available, restrict access to the plugin’s admin pages by allowing only administrator roles or by blocking unauthenticated requests to the plugin’s URLs with a firewall or security plugin.
  • If the plugin’s functionality is not required, disable or uninstall the Mobile Contact Line plugin entirely.

Generated by OpenCVE AI on April 30, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26545 Missing Authorization vulnerability in yydevelopment Mobile Contact Line allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile Contact Line: from n/a through 2.4.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in yydevelopment Mobile Contact Line allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile Contact Line: from n/a through 2.4.0. Missing Authorization vulnerability in yydevelopment Mobile Contact Line mobile-contact-line allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile Contact Line: from n/a through <= 2.4.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 03 Sep 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Yydevelopment
Yydevelopment mobile Contact Line Plugin
Vendors & Products Wordpress
Wordpress wordpress
Yydevelopment
Yydevelopment mobile Contact Line Plugin

Wed, 03 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Sep 2025 14:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in yydevelopment Mobile Contact Line allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mobile Contact Line: from n/a through 2.4.0.
Title WordPress Mobile Contact Line Plugin <= 2.4.0 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Yydevelopment Mobile Contact Line Plugin
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:44.323Z

Reserved: 2025-09-03T09:03:04.975Z

Link: CVE-2025-58622

cve-icon Vulnrichment

Updated: 2025-09-03T17:36:34.737Z

cve-icon NVD

Status : Deferred

Published: 2025-09-03T15:15:45.050

Modified: 2026-04-23T15:33:28.783

Link: CVE-2025-58622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T03:00:15Z

Weaknesses