Missing Authorization Flaw in PluginEver WP Content Pilot by WordPress
CVE-2025-64263

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 November 2025

What is CVE-2025-64263?

A missing authorization vulnerability exists in the PluginEver WP Content Pilot plugin, permitting attackers to exploit poorly configured access control mechanisms. This vulnerability can lead to unauthorized access to sensitive functionalities within the plugin, allowing potentially unauthorized actions that could impact website security and integrity. Affected versions include all prior to 2.1.7. It is crucial for users to assess their systems and apply necessary updates to mitigate potential risks.

Affected Version(s)

WP Content Pilot <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.
CVE-2025-64263 : Missing Authorization Flaw in PluginEver WP Content Pilot by WordPress