Missing Authorization Vulnerability in Patreon Plugin for WordPress
CVE-2025-24588
6.5MEDIUM
What is CVE-2025-24588?
A missing authorization vulnerability exists in the Patreon WordPress plugin, allowing attackers to exploit incorrectly configured access control security levels. This flaw affects versions from n/a through 1.9.1, potentially granting unauthorized access to sensitive functionalities. It is crucial for users to review their configurations to mitigate risks associated with this security issue.
Affected Version(s)
Patreon WordPress <= 1.9.1