Description
Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Virtual Assistant: from n/a through <= 3.0.
Published: 2025-09-26
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw that allows exploitation of incorrectly configured access control levels in the loopus WP Virtual Assistant plugin. The lack of proper checks can enable an attacker to exercise functions beyond their intended permissions, potentially modifying plugin settings, viewing or submitting data that should be restricted, and undermining the confidentiality and integrity of the site’s content. The weakness is identified as CWE-862, a classic lack of access control issue.

Affected Systems

Affected are WordPress sites running the loopus WP Virtual Assistant plugin, versions from the earliest available up to and including 3.0. Any site still using a 3.0 or older release is vulnerable unless a newer version is installed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of <1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. The most likely attack path involves a user who can authenticate to the WordPress administration interface but lacks sufficient permissions; such a user may be able to access plugin pages that do not enforce the correct role or capability checks. Exploiting the flaw could enable unauthorized actions within the plugin without requiring elevated privileges.

Generated by OpenCVE AI on April 29, 2026 at 23:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Virtual Assistant plugin to a version newer than 3.0 as released by the vendor.
  • Reconfigure the plugin’s access restrictions to enforce proper WordPress capability checks and limit functionality to appropriate user roles.
  • Audit site user roles and plugin logs for any anomalous activity that could indicate misuse.

Generated by OpenCVE AI on April 29, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-31250 Missing Authorization vulnerability in loopus WP Virtual Assistant allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Virtual Assistant: from n/a through 3.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in loopus WP Virtual Assistant allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Virtual Assistant: from n/a through 3.0. Missing Authorization vulnerability in loopus WP Virtual Assistant VirtualAssistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Virtual Assistant: from n/a through <= 3.0.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Mon, 29 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 26 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Sep 2025 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in loopus WP Virtual Assistant allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Virtual Assistant: from n/a through 3.0.
Title WordPress WP Virtual Assistant Plugin <= 3.0 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:55.850Z

Reserved: 2025-09-25T15:28:03.107Z

Link: CVE-2025-60155

cve-icon Vulnrichment

Updated: 2025-09-26T14:27:16.262Z

cve-icon NVD

Status : Deferred

Published: 2025-09-26T09:15:44.360

Modified: 2026-06-17T09:49:27.657

Link: CVE-2025-60155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T00:00:14Z

Weaknesses