Description
Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1.
Published: 2025-12-24
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization enforcement was discovered in the WP Adminify plugin for WordPress, allowing attackers to perform actions normally restricted to privileged users. The flaw enables unauthorized users to access, configure, or delete settings within the plugin, potentially compromising the integrity and confidentiality of the site’s administration functions. The weakness corresponds to CWE-862, which focuses on improper role or privilege checking. Vulnerabilities of this nature can lead to unauthorized configuration changes and are a concern for administrators and security teams managing WordPress instances.

Affected Systems

The affected vendor is Liton Arefin, the WP Adminify plugin. All releases from the earliest version through version 4.0.6.1 are impacted; no specific patch version is provided in the advisory, so any version numbered 4.0.6.1 or earlier is considered vulnerable. No other WordPress plugins or core WordPress components are listed as affected.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of assessment. The vulnerability is not present in the CISA KEV catalog, so no large-scale exploit campaigns are known. Based on the description, it is inferred that the likely attack vector is through the plugin’s administrative interface, where an attacker may authenticate with compromised or weak credentials or may bypass authentication entirely due to missing access checks. Attacker execution is possible remotely via the WordPress admin dashboard and does not require local privileges on the hosting machine.

Generated by OpenCVE AI on April 29, 2026 at 18:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Adminify plugin to the latest patched release that eliminates the broken access control flaw.
  • If an immediate upgrade is not possible, temporarily disable the plugin by removing or renaming its files so that the vulnerable code can no longer be accessed.
  • Configure role‑based access control in WordPress so that only administrators are allowed to use the plugin’s settings pages, and review permission settings to ensure no unnecessary roles have elevated access.

Generated by OpenCVE AI on April 29, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1.
Title WordPress WP Adminify plugin <= 4.0.6.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:31.227Z

Reserved: 2025-12-19T10:17:41.811Z

Link: CVE-2025-68593

cve-icon Vulnrichment

Updated: 2025-12-24T18:46:25.556Z

cve-icon NVD

Status : Deferred

Published: 2025-12-24T13:16:26.697

Modified: 2026-04-27T19:16:34.903

Link: CVE-2025-68593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:30:17Z

Weaknesses