Missing Authorization Issue in RestroPress by Magnigenie
CVE-2025-66100

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 December 2025

What is CVE-2025-66100?

A Missing Authorization vulnerability has been identified in the RestroPress plugin by Magnigenie, which can allow unauthorized access due to incorrectly configured access control security levels. This flaw affects users of RestroPress from its earliest version to 3.2.3.5, making it crucial for website administrators to update and secure their installations to prevent potential exploitation.

Affected Version(s)

RestroPress <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.
CVE-2025-66100 : Missing Authorization Issue in RestroPress by Magnigenie