Missing Authorization Flaw in Stop and Block Bots Plugin by Bill Minozzi
CVE-2025-48166
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 July 2025
What is CVE-2025-48166?
A missing authorization vulnerability in the Stop and Block Bots plugin allows attackers to access functionalities that are not properly safeguarded by Access Control Lists (ACLs). This oversight affects all versions up to and including 1.48, potentially exposing sensitive features to unauthorized users.
Affected Version(s)
Stop and Block bots plugin Anti bots <= 1.48