CVE Details
Basic Information
| Title | CVE-2025-26867 |
|---|---|
| Type | cve |
| Published | 2025-05-19T17:15:23 |
| Last Seen | 2025-05-19T17:23:39 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | LOW |
| Availability Impact | NONE |
AI Analysis
| AI Description | A missing authorization vulnerability in Themes4WP Bulk allows unauthorized access to functionality that should be constrained by ACLs. This could enable attackers to perform actions they shouldn’t be able to. The issue affects versions from n/a through 1.0.11. |
|---|---|
| AI Severity | Medium |
| Vendor | WordPress Community |
| Product | Themes4WP Bulk |
| Affected Version | n/a, 1.0.11 |
Additional Information
| CVE List | CVE-2025-26867 |
|---|---|
| CWE List | CWE-862 |
| Bulletin Family | cve |
Description
Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n/a through 1.0.11.
CVSS Score Summary
Base Score: %!f(string=#) (MEDIUM)