Unauthorized Data Deletion Vulnerability in Aeropage Sync for Airtable Plugin by WordPress
CVE-2025-3915
4.3MEDIUM
What is CVE-2025-3915?
The Aeropage Sync for Airtable plugin for WordPress contains a serious flaw that allows authenticated users with Subscriber-level access and higher to delete any post without proper permission checks. This vulnerability stems from a missing capability validation in the 'aeropageDeletePost' function, potentially leading to significant data loss and undermining user control. It affects all versions of the plugin up to 3.2.0, posing a serious risk for site administrators who utilize this integration.
Affected Version(s)
Aeropage Sync for Airtable * <= 3.2.0