Missing Authorization in Easy Theme Options Plugin for WordPress
CVE-2025-14367
5.3MEDIUM
What is CVE-2025-14367?
The Easy Theme Options plugin for WordPress is impacted by a Missing Authorization flaw, present in all versions up to and including 1.0. This vulnerability arises due to inadequate authorization checks in the 'eto_import_settings' function. As a result, attackers with Subscriber-level access or higher can potentially exploit this weakness to import arbitrary plugin settings using the 'eto_import_settings' parameter, compromising the security and integrity of the WordPress site.
Affected Version(s)
Easy Theme Options * <= 1.0