Description
Missing Authorization vulnerability in NicolasKulka WPS Bidouille wps-bidouille allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPS Bidouille: from n/a through <= 1.33.1.
Published: 2025-12-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization defect in the WPS Bidouille plugin that can be exploited when the plugin’s access control security levels are incorrectly configured. An attacker who can interact with the plugin’s administrative interfaces may gain unauthorized permission to modify or view settings that should be restricted. This permits manipulation of configuration data, potentially enabling further compromise of a WordPress site. The weakness corresponds to CWE‑862, where the lack of proper access checks allows privilege escalation within the application.

Affected Systems

The flaw affects the WordPress plugin WPS Bidouille developed by NicolasKulka. All releases from the earliest up to and including version 1.33.1 are impacted. No higher versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, implying no known active exploit activity. Based on the description, the likely attack vector is a remote web-based request that an attacker can send to the WordPress site to access restricted plugin functionality without proper authorization. No special system privileges or external conditions beyond the ability to send HTTP requests are required to exercise the flaw.

Generated by OpenCVE AI on April 29, 2026 at 19:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPS Bidouille to a version newer than 1.33.1 to apply the vendor’s fix
  • If an upgrade is not immediately possible, uninstall or deactivate the plugin to eliminate the attack surface
  • Restrict WordPress role permissions so that only users with the administrator role can access the plugin’s configuration pages

Generated by OpenCVE AI on April 29, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 16 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in NicolasKulka WPS Bidouille wps-bidouille allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPS Bidouille: from n/a through <= 1.33.1.
Title WordPress WPS Bidouille plugin <= 1.33.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:11.545Z

Reserved: 2025-10-29T03:08:12.202Z

Link: CVE-2025-64238

cve-icon Vulnrichment

Updated: 2025-12-16T17:31:07.830Z

cve-icon NVD

Status : Deferred

Published: 2025-12-16T09:15:53.247

Modified: 2026-06-17T09:54:04.170

Link: CVE-2025-64238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:15:18Z

Weaknesses