Description
Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through <= 4.9.5.
Published: 2025-12-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to exploit improperly configured access‑control security settings within the wpstream plugin. This flaw does not provide arbitrary code execution but can let a malicious actor access privileged content or perform actions they should not be permitted to, thereby compromising confidentiality and potentially allowing unauthorized data retrieval or manipulation.

Affected Systems

This issue affects the WordPress plugin WpStream, from the earliest released version up through and including version 4.9.5. All installations running any of these versions are potentially vulnerable, regardless of the WordPress core version. No specific WordPress version requirement is noted.

Risk and Exploitability

The CVSS score of 4.3 categorizes the vulnerability as moderate severity, while the EPSS score of less than 1% points to a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and there is currently no evidence of active exploitation in the wild. The likely attack vector is remote, via the web interface of the plugin, taking advantage of insufficient authorization checks. Due to the moderate score and low exploitation probability, this issue represents a lower‑to‑moderate risk that still warrants remediation to prevent potential unauthorized data access.

Generated by OpenCVE AI on April 29, 2026 at 15:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the wpstream plugin to a version that addresses the authorization flaw (any release newer than 4.9.5).
  • Review and correct the plugin’s role‑based access settings to ensure only authorized user roles can invoke the affected functionality.
  • If an update is not immediately possible, temporarily disable the plugin or apply server‑level restrictions (e.g., file permissions or URL blocking) to limit access to the plugin’s components.

Generated by OpenCVE AI on April 29, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpstream
Wpstream wpstream
Vendors & Products Wordpress
Wordpress wordpress
Wpstream
Wpstream wpstream

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through <= 4.9.5.
Title WordPress WpStream plugin <= 4.9.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
Wpstream Wpstream
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:29.218Z

Reserved: 2025-12-19T10:16:57.339Z

Link: CVE-2025-68522

cve-icon Vulnrichment

Updated: 2025-12-24T19:09:29.037Z

cve-icon NVD

Status : Deferred

Published: 2025-12-24T13:16:21.763

Modified: 2026-04-27T19:16:27.770

Link: CVE-2025-68522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:45:14Z

Weaknesses