Description
Missing Authorization vulnerability in Apiki GoCache gocache-cdn allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GoCache: from n/a through <= 1.3.6.
Published: 2025-10-27
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Apiki GoCache plugin that allows attackers to access or modify resources protected by the plugin’s access control settings. This broken access control can lead to unauthorized viewing or alteration of content, potentially exposing sensitive data and compromising the integrity of the site. The weakness is classified as CWE‑862 and is specifically described as an incorrectly configured access control security level that can be exploited.

Affected Systems

Vendors and products affected are Apiki’s GoCache plugin for WordPress. The issue applies to all releases from the earliest version through 1.3.6, inclusive. No later version information is available in the current advisory, indicating that versions newer than 1.3.6 should be examined for fixes.

Risk and Exploitability

The CVSS score of 5.4 places this vulnerability in a moderate risk category. The EPSS score of less than 1 % indicates a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is through access to the plugin’s internal URLs or APIs from the web interface; an attacker with unauthenticated or limited access could use these endpoints to bypass intended restrictions. No additional prerequisites are mentioned beyond the presence of the vulnerable plugin on a WordPress site.

Generated by OpenCVE AI on April 29, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GoCache WordPress plugin to the latest version where the missing authorization issue is resolved.
  • If an immediate update is not available, restrict access to the plugin’s administrative endpoints by applying role‑based access controls or a firewall rule that allows only trusted users such as administrators.
  • Review and enforce the principle of least privilege for all WordPress users and disable or remove the plugin if it cannot be patched in a timely manner.

Generated by OpenCVE AI on April 29, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Mon, 27 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 02:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Apiki GoCache gocache-cdn allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GoCache: from n/a through <= 1.3.6.
Title WordPress GoCache plugin <= 1.3.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:07.238Z

Reserved: 2025-10-24T14:25:01.200Z

Link: CVE-2025-62966

cve-icon Vulnrichment

Updated: 2025-10-27T14:40:00.824Z

cve-icon NVD

Status : Deferred

Published: 2025-10-27T02:15:56.940

Modified: 2026-04-27T17:16:38.573

Link: CVE-2025-62966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:30:19Z

Weaknesses