Description
Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.40.
Published: 2025-12-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Custom Admin Interface plugin includes a missing authorization check that allows an authenticated or potentially unauthenticated attacker to perform privileged actions within the admin interface. This broken access control means the attacker could add, edit, or delete configuration settings, potentially granting themselves elevated privileges or altering site functionality. The primary impact is privilege escalation, as the vulnerability directly bypasses intended access restrictions.

Affected Systems

Affected systems include any WordPress installation that uses the Northern Beaches Websites WP Custom Admin Interface plugin in versions up through and including 7.40. The issue applies to all builds from the earliest available version up to 7.40, regardless of minor releases. Administrators should verify they are running a version newer than 7.40 before addressing the risk.

Risk and Exploitability

Risk assessment relies on a CVSS score of 4.3, indicating moderate severity, and an EPSS score of less than 1%, suggesting low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would occur via the WordPress administrative interface, requiring the attacker to authenticate or otherwise gain access to an account with sufficient privileges. In practice, the risk remains limited but should be mitigated promptly.

Generated by OpenCVE AI on April 29, 2026 at 17:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Custom Admin Interface plugin to a version newer than 7.40, ensuring the missing authorization check is resolved.
  • If an immediate upgrade is not feasible, restrict access to the plugin’s administrative pages by applying IP-based restrictions or .htaccess rules to limit who can reach those URLs.
  • Review and tighten user roles and capabilities associated with the plugin, removing any unnecessary admin privileges from standard users.

Generated by OpenCVE AI on April 29, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.40. Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.40.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Northern Beaches Websites
Northern Beaches Websites wp Custom Admin Interface
Wordpress
Wordpress wordpress
Vendors & Products Northern Beaches Websites
Northern Beaches Websites wp Custom Admin Interface
Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.40.
Title WordPress WP Custom Admin Interface plugin <= 7.40 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Northern Beaches Websites Wp Custom Admin Interface
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:09.180Z

Reserved: 2025-10-24T14:25:50.122Z

Link: CVE-2025-63038

cve-icon Vulnrichment

Updated: 2025-12-31T17:33:01.966Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T17:15:48.583

Modified: 2026-04-23T15:34:59.900

Link: CVE-2025-63038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:00:13Z

Weaknesses