Missing Authorization Flaw in WP Email Capture by Rhys Wynne
CVE-2025-67578

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 December 2025

What is CVE-2025-67578?

The WP Email Capture plugin developed by Rhys Wynne contains a missing authorization vulnerability that can be exploited due to improperly configured access controls. This flaw allows unauthorized users to gain access to restricted functionalities, potentially compromising sensitive data. The vulnerability affects all versions of WP Email Capture from its initial release up to and including version 3.12.4, requiring immediate attention to safeguard user data and maintain website integrity.

Affected Version(s)

WP Email Capture <= n/a

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.
CVE-2025-67578 : Missing Authorization Flaw in WP Email Capture by Rhys Wynne