CVE-2025-12579
Description
The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'logoff' action in all versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to reset the plugin's settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Reuters Direct WordPress plugin lacks a capability check on the 'logoff' action, allowing unauthenticated attackers to reset plugin settings.
Vulnerability
Overview The Reuters Direct plugin for WordPress, up to version 3.0.0, contains a missing capability check on the 'logoff' action. This vulnerability allows unauthorized modification of the plugin's settings, as the action does not verify user permissions before execution [1].
Exploitation
Details An unauthenticated attacker can exploit this by sending a crafted request to the 'logoff' action endpoint without any authentication. No special privileges or network position are required, making it easily accessible to any visitor of a WordPress site using the vulnerable plugin [1].
Impact
Successful exploitation resets the plugin's settings to default values, potentially disrupting news feeds or configured options. This could lead to a loss of data integrity and minor service disruption, though it does not compromise the core WordPress installation or other plugins [1].
Mitigation
Status The plugin has been closed as of November 25, 2025, due to this security issue and is no longer available for download [1]. Users are advised to remove the plugin entirely from their WordPress installations to eliminate the risk. No patch is available for existing versions.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=3.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.