Missing Authorization Vulnerability in Vanquish User Extra Fields Plugin
CVE-2025-67579
5.3MEDIUM
What is CVE-2025-67579?
The Vanquish User Extra Fields plugin for WordPress is susceptible to a missing authorization vulnerability, which arises from incorrectly configured access control settings. This flaw allows unauthorized users to exploit the system and gain access to sensitive functionalities that should require authentication. The affected versions of the plugin range from an unspecified version to 16.8, highlighting the need for an update or remedial action to secure user data and functionalities against potential exploitation.
Affected Version(s)
User Extra Fields <= n/a
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Phat RiO - BlueRock | Patchstack Bug Bounty Program