Description
Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leaky Paywall: from n/a through <= 4.22.6.
Published: 2025-12-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Leaky Paywall plugin contains a missing authorization check that allows any user to access content intended to be restricted. This broken access control vulnerability exposes confidential material to unauthenticated or improperly authorized parties. The flaw is classified as CWE‑862 and can enable an attacker to retrieve premium posts, pages, or other protected resources without paying or logging in.

Affected Systems

The affected product is the Zeen101 Leaky Paywall WordPress plugin. All releases up to and including version 4.22.6 are impacted, from the earliest available version through 4.22.6. Users running any of these versions on WordPress sites should consider the plugin vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can simply request the URLs of protected content or send crafted requests to bypass the plugin’s access checks, enabling the exposure of restricted material without needing privileged credentials.

Generated by OpenCVE AI on April 29, 2026 at 19:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest plugin version (4.22.7 or later) which contains the authorization fix.
  • If an upgrade is not immediately feasible, disable or remove the Leaky Paywall plugin to prevent the exposure of protected content.
  • In the interim, enforce stricter WordPress role permissions and use a security plugin to block unauthorized access to premium pages.

Generated by OpenCVE AI on April 29, 2026 at 19:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leaky Paywall: from n/a through <= 4.22.5. Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leaky Paywall: from n/a through <= 4.22.6.
Title WordPress Leaky Paywall plugin <= 4.22.5 - Broken Access Control vulnerability WordPress Leaky Paywall plugin <= 4.22.6 - Broken Access Control vulnerability

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Zeen101
Zeen101 leaky Paywall
Vendors & Products Wordpress
Wordpress wordpress
Zeen101
Zeen101 leaky Paywall

Tue, 16 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in ZEEN101 Leaky Paywall leaky-paywall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leaky Paywall: from n/a through <= 4.22.5.
Title WordPress Leaky Paywall plugin <= 4.22.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
Zeen101 Leaky Paywall
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:17.556Z

Reserved: 2025-11-21T11:21:32.202Z

Link: CVE-2025-66124

cve-icon Vulnrichment

Updated: 2025-12-16T17:25:16.321Z

cve-icon NVD

Status : Deferred

Published: 2025-12-16T09:15:56.700

Modified: 2026-04-27T17:16:40.570

Link: CVE-2025-66124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:15:18Z

Weaknesses