Missing Authorization in Essential Plugin Featured Post Creative by Patchstack
CVE-2025-66106

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
21 November 2025

What is CVE-2025-66106?

A missing authorization vulnerability exists in the Essential Plugin Featured Post Creative, which could allow attackers to exploit incorrectly configured access control security levels. This vulnerability affects the plugin in versions from n/a to 1.5.5, potentially enabling unauthorized users to gain access to restricted features or data.

Affected Version(s)

Featured Post Creative <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.
CVE-2025-66106 : Missing Authorization in Essential Plugin Featured Post Creative by Patchstack