Authorization Flaw in WP Messiah Swiss Toolkit Affects Access Control Mechanisms
CVE-2025-31544

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 March 2025

What is CVE-2025-31544?

The WP Messiah Swiss Toolkit for WP suffers from a significant missing authorization vulnerability that allows attackers to exploit incorrectly configured access control security levels. This flaw can potentially lead to unauthorized access to restricted areas of the website, exposing sensitive data and functionalities. All installations of the toolkit from version 'n/a' up to 1.3.0 are at risk, making it imperative for users to review their access control settings immediately to protect against potential exploitation.

Affected Version(s)

Swiss Toolkit For WP <= 1.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis (Patchstack Alliance)
.