Description
Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1.
Published: 2025-12-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing Authorization (CWE‑862) in Liton Arefin WP Adminify allows exploitation of incorrectly configured access control security levels. An attacker can gain unauthorized administrative capabilities without proper authentication, potentially modifying site content, settings or accessing sensitive data. The flaw impairs confidentiality, integrity, and availability by granting full control over the WordPress installation.

Affected Systems

Liton Arefin’s WP Adminify plugin is affected from all versions up to and including 4.0.6.1. Users running any of these versions on WordPress sites are vulnerable. The plugin provides administrative tools, so any WordPress instance that has the plugin installed and configured with default or inadequate access settings is at risk.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity flaw, while an EPSS score of less than 1 percent suggests a low exploitation probability at present. It is inferred that the plugin’s web‑based interface is the likely attack surface, and that the missing authorization check indicates that no valid authentication is required to achieve elevated privileges. Though listed as not in KEV, the absence of a known public exploit does not diminish the risk for organizations that have the vulnerable plugin installed.

Generated by OpenCVE AI on April 29, 2026 at 22:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Adminify plugin to the newest available version (any release above 4.0.6.1) to patch the missing authorization flaw.
  • Reconfigure the plugin’s access control settings so that only users with appropriate roles can perform administrative functions.
  • Audit user accounts and administrative activity on the WordPress site to detect any unauthorized access, then disable or remove any suspicious accounts.

Generated by OpenCVE AI on April 29, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1.
Title WordPress WP Adminify plugin <= 4.0.6.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:31.246Z

Reserved: 2025-12-19T10:17:41.811Z

Link: CVE-2025-68592

cve-icon Vulnrichment

Updated: 2025-12-24T18:46:39.365Z

cve-icon NVD

Status : Deferred

Published: 2025-12-24T13:16:26.573

Modified: 2026-04-27T19:16:34.787

Link: CVE-2025-68592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:15:16Z

Weaknesses