Missing Authorization Vulnerability in Md Yeasin Ul Haider URL Shortener by Patchstack
CVE-2025-28965

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 July 2025

What is CVE-2025-28965?

A missing authorization vulnerability in the Md Yeasin Ul Haider URL Shortener allows unauthorized access to functionalities not properly constrained by Access Control Lists (ACLs). This can potentially expose sensitive operations to users without the required permissions, affecting versions from 3.0.7 and earlier.

Affected Version(s)

URL Shortener <= 3.0.7

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ch4r0n (Patchstack Alliance)
.
CVE-2025-28965 : Missing Authorization Vulnerability in Md Yeasin Ul Haider URL Shortener by Patchstack