Missing Authorization Vulnerability in Vanquish User Extra Fields Plugin
CVE-2025-67579

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 December 2025

What is CVE-2025-67579?

The Vanquish User Extra Fields plugin for WordPress is susceptible to a missing authorization vulnerability, which arises from incorrectly configured access control settings. This flaw allows unauthorized users to exploit the system and gain access to sensitive functionalities that should require authentication. The affected versions of the plugin range from an unspecified version to 16.8, highlighting the need for an update or remedial action to secure user data and functionalities against potential exploitation.

Affected Version(s)

User Extra Fields <= n/a

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock | Patchstack Bug Bounty Program
.