Incorrect Privilege Assignment in Site Offline Plugin by chandrashekharsahu
CVE-2025-48348
4.3MEDIUM
What is CVE-2025-48348?
An Incorrect Privilege Assignment vulnerability discovered in the Site Offline plugin from chandrashekharsahu allows for the exploitation of misconfigured access control security levels. This flaw could permit unauthorized users to gain access to sensitive functionalities within the site, leading to potential data breaches or unauthorized modifications. Users utilizing versions n/a through 1.5.7 are at risk and should review their access control configurations urgently.
Affected Version(s)
Site Offline <= 1.5.7