Access Control Flaw in Worker for WPBakery by merkulove
CVE-2025-66145
5.4MEDIUM
What is CVE-2025-66145?
A missing authorization vulnerability exists in Worker for WPBakery by merkulove, allowing attackers to exploit improperly configured access controls. This specific issue can lead to unauthorized actions, potentially compromising sensitive information and application integrity. Users of versions up to 1.1.1 need to address this access control flaw promptly to maintain security.
Affected Version(s)
Worker for WPBakery <= 1.1.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Phat RiO - BlueRock | Patchstack Bug Bounty Program