Missing Authorization in Wikimedia Foundation Mediawiki - AbuseFilter Extension
CVE-2025-53499

Currently unrated

What is CVE-2025-53499?

A Missing Authorization vulnerability has been identified in the AbuseFilter Extension of the Mediawiki product by the Wikimedia Foundation. This flaw permits unauthorized users to access restricted functionalities, potentially allowing them to exploit the system. Users of affected versions, specifically those prior to 1.39.13, 1.42.7, and 1.43.2, should take immediate action to update their instances to the latest versions to mitigate this security risk. For further details, refer to the provided references.

Affected Version(s)

Mediawiki - AbuseFilter Extension 1.39.x

Mediawiki - AbuseFilter Extension 1.39.x < 1.39.13

Mediawiki - AbuseFilter Extension 1.42.x < 1.42.7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dreamy_Jazz
.
CVE-2025-53499 : Missing Authorization in Wikimedia Foundation Mediawiki - AbuseFilter Extension