4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Description
The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on the 'sweet_energy_efficiency_action' AJAX handler in all versions up to, and including, 1.0.6. This makes it possible for authenticated attackers, with subscriber level access and above, to read, modify, and delete arbitrary graphs.
Basic Information
ID
CVE-2025-14618
Source
Wordfence
Published
Dec 18, 2025 at 12:22
Affected Product
Vendor
listingthemes
Product
Sweet Energy Efficiency
Version
*
Affected Versions
listingthemes Sweet Energy Efficiency *