Unauthorized Page Creation in CodeConfig Accessibility Plugin for WordPress
CVE-2025-13358
What is CVE-2025-13358?
The CodeConfig Accessibility plugin for WordPress, up to version 1.0.0, allows authenticated users with Subscriber-level access or higher to exploit a lack of authorization checks. The vulnerability arises in the Settings::createPage() function, which does not enforce capability checks, enabling attackers to create arbitrary published pages through the ccpcaCreatePage AJAX action. This flaw can lead to unauthorized content creation on a WordPress site, potentially compromising the integrity and security of the web application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CodeConfig Accessibility * <= 1.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved