Description
Missing Authorization vulnerability in favethemes Homey Core homey-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Homey Core: from n/a through <= 2.4.3.
Published: 2025-12-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to bypass incorrectly configured access control levels within the Homey Core plugin. This results in a broken access control weakness (CWE-862) that can enable unauthorized access to restricted content or administrative functions of a WordPress site. The impact is elevating the user privileges of an attacker, potentially exposing sensitive data or allowing further exploitation if other weaknesses are present.

Affected Systems

Affected systems are WordPress sites running the Homey Core plugin from favethemes, with versions up to and including 2.4.3. All installations of Homey Core on these versions are vulnerable until the plugin is upgraded beyond 2.4.3.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation in the wild. Because the issue stems from missing authorization in the plugin code, the likely attack vector is a web-based request to a protected resource, such as an admin endpoint or a page that should be restricted. Although not listed in CISA’s KEV catalog, administrators should still address the issue promptly to eliminate the risk of privilege escalation on their sites.

Generated by OpenCVE AI on April 27, 2026 at 22:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Homey Core to version 2.4.4 or later to fix the broken access control bug.
  • If an upgrade cannot be performed immediately, disable or delete the Homey Core plugin from the WordPress installation.
  • Reconfigure WordPress role and capability settings to ensure that only authorized users can access administrative functions, particularly those provided by Homey Core.

Generated by OpenCVE AI on April 27, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Favethemes
Favethemes homey
Wordpress
Wordpress wordpress
Vendors & Products Favethemes
Favethemes homey
Wordpress
Wordpress wordpress

Tue, 16 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in favethemes Homey Core homey-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Homey Core: from n/a through <= 2.4.3.
Title WordPress Homey Core plugin <= 2.4.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Favethemes Homey
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:24.907Z

Reserved: 2025-12-15T10:00:23.852Z

Link: CVE-2025-67965

cve-icon Vulnrichment

Updated: 2025-12-16T19:07:30.050Z

cve-icon NVD

Status : Deferred

Published: 2025-12-16T09:15:59.970

Modified: 2026-04-27T18:16:51.747

Link: CVE-2025-67965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T22:30:14Z

Weaknesses