Authorization Flaw in NotFound Site Notify Affects Access Control Settings
CVE-2025-32240
6.5MEDIUM
What is CVE-2025-32240?
The NotFound Site Notify plugin for WordPress has a missing authorization vulnerability that can lead to improperly configured access control settings. This flaw enables unauthorized users to exploit the system, potentially gaining access to sensitive features and data. The issue affects versions from n/a through 1.0, emphasizing the need for immediate attention and remediation to secure WordPress sites utilizing this plugin.
Affected Version(s)
Site Notify <= 1.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published