Description
Missing Authorization vulnerability in AppMySite AppMySite appmysite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AppMySite: from n/a through <= 3.15.0.
Published: 2025-09-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AppMySite plugin for WordPress is affected by a missing authorization flaw that permits users to exploit incorrectly configured access control settings. This vulnerability, identified under CWE‑862, enables an attacker to perform actions that should be restricted to privileged accounts, potentially giving access to sensitive data or administrative functions within the site. The risk is a moderate breach of confidentiality or integrity depending on the attacker’s role and the functions exposed by the plugin.

Affected Systems

Customers running the AppMySite plugin with a version of 3.15.0 or earlier are impacted. The plugin is distributed through the WordPress ecosystem, and any site that has installed AppMySite prior to version 3.15.1 must review its deployment. Older or unspecified versions of AppMySite up through 3.15.0 are also vulnerable due to the same authorization oversight.

Risk and Exploitability

The assessed CVSS score is 5.3, indicating moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, further indicating that it has not yet been observed in widespread attacks. Exploitability is likely achieved via web requests to the plugin’s endpoints using valid credentials; the attacker can abuse the plugin’s functionality without needing elevated privileges initially. The most effective attack scenario involves authenticating as a standard user and then interacting with privileged plugin routes to bypass intended restrictions.

Generated by OpenCVE AI on April 30, 2026 at 01:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AppMySite plugin to the latest released version that addresses the missing authorization issue.
  • If an upgrade is not immediately possible, temporarily deactivate or remove the plugin until a patch is applied.
  • Review the site’s role‑based access controls and ensure that only authorized roles have access to the plugin’s features, especially if the plugin remains in use for an extended period.

Generated by OpenCVE AI on April 30, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30527 Missing Authorization vulnerability in AppMySite AppMySite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AppMySite: from n/a through 3.14.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in AppMySite AppMySite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AppMySite: from n/a through 3.14.0. Missing Authorization vulnerability in AppMySite AppMySite appmysite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AppMySite: from n/a through <= 3.15.0.
Title WordPress AppMySite Plugin <= 3.14.0 - Broken Access Control Vulnerability WordPress AppMySite plugin <= 3.15.0 - Broken Access Control vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Appmysite
Appmysite appmysite
Wordpress
Wordpress wordpress
Vendors & Products Appmysite
Appmysite appmysite
Wordpress
Wordpress wordpress

Tue, 23 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in AppMySite AppMySite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AppMySite: from n/a through 3.14.0.
Title WordPress AppMySite Plugin <= 3.14.0 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Appmysite Appmysite
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:46.213Z

Reserved: 2025-09-03T09:03:46.832Z

Link: CVE-2025-58679

cve-icon Vulnrichment

Updated: 2025-09-23T13:57:48.721Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:19.290

Modified: 2026-04-23T15:33:34.900

Link: CVE-2025-58679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T02:00:13Z

Weaknesses