Access Control Misconfiguration in WPGuppy by Amento Tech Pvt Ltd
CVE-2025-24643
6.5MEDIUM
What is CVE-2025-24643?
A vulnerability in WPGuppy, developed by Amento Tech Pvt Ltd, is attributed to missing authorization, which can lead to improperly configured access control settings. This flaw allows attackers to exploit security-level misconfigurations, potentially granting unauthorized access to sensitive functions. Users of WPGuppy versions from n/a to 1.1.0 are particularly at risk, thus necessitating immediate security assessments and updates to mitigate the exposure.
Affected Version(s)
WPGuppy <= 1.1.0