Missing Authorization Vulnerability in JSM Show Post Metadata by JS Morisset
CVE-2025-24589
4.3MEDIUM
What is CVE-2025-24589?
A missing authorization vulnerability in the JSM Show Post Metadata plugin allows attackers to exploit improperly configured access control settings. This flaw can lead to unauthorized access to sensitive metadata, potentially exposing private information and compromising the security of the affected WordPress installations. It is crucial for site administrators to update their plugins and implement proper access control measures to mitigate this security risk.
Affected Version(s)
JSM Show Post Metadata 0 <= 4.6.0