Authorization Bypass in Alex Content Mask by WordPress
CVE-2025-58012

3.8LOW

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-58012?

An authorization bypass vulnerability exists in the Alex Content Mask plugin, allowing attackers to exploit incorrect access control configurations. This could lead to unauthorized access to restricted resources, compromising the integrity and security of user data. The issue affects versions ranging from 1.0.0 to 1.8.5.2, necessitating immediate attention to ensure proper security measures are in place.

Affected Version(s)

Content Mask <= 1.8.5.2

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.