Missing Authorization Flaw in Rocket Apps wProject
CVE-2025-39350
8.2HIGH
What is CVE-2025-39350?
A missing authorization vulnerability exists in Rocket Apps wProject, allowing unauthenticated users to modify and delete comments and attachments. This flaw can lead to unauthorized actions on user-generated content, impacting the integrity of the website. Users of wProject versions prior to 5.8.0 should update to mitigate potential security risks.
Affected Version(s)
wProject < 5.8.0