Missing Authorization Flaw in WP Email Capture by Rhys Wynne
CVE-2025-67578
5.3MEDIUM
What is CVE-2025-67578?
The WP Email Capture plugin developed by Rhys Wynne contains a missing authorization vulnerability that can be exploited due to improperly configured access controls. This flaw allows unauthorized users to gain access to restricted functionalities, potentially compromising sensitive data. The vulnerability affects all versions of WP Email Capture from its initial release up to and including version 3.12.4, requiring immediate attention to safeguard user data and maintain website integrity.
Affected Version(s)
WP Email Capture <= n/a
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nabil Irawan | Patchstack Bug Bounty Program