VYPR
Medium severity4.3NVD Advisory· Published Apr 1, 2025· Updated Apr 23, 2026

CVE-2025-31787

CVE-2025-31787

Description

Missing authorization vulnerability in Cue plugin <=2.4.4 allows attackers to exploit incorrectly configured access control security levels.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization vulnerability in Cue plugin <=2.4.4 allows attackers to exploit incorrectly configured access control security levels.

Vulnerability

The Cue plugin by AudioTheme (cue) contains a missing authorization vulnerability in versions up to and including 2.4.4 [1]. The bug allows exploitation of incorrectly configured access control security levels, meaning that certain functionality or data may be accessed without proper permission checks [1].

Exploitation

An attacker would need to be authenticated as a user with some level of access to the WordPress site, as the vulnerability stems from missing authorization checks rather than missing authentication [1]. The exact sequence of steps is not disclosed in the available references, but the attacker leverages the insufficient access control to reach protected functionality [1].

Impact

Successful exploitation leads to unauthorized access to features or data that should be restricted to higher-privilege users [1]. The impact is limited by the CVSS score of 4.3 (Medium), indicating partial compromise of confidentiality or integrity without full system takeover [1].

Mitigation

The vulnerability is fixed in version 2.4.5 of the Cue plugin, released on 2025-04-02 [1]. Users should update to version 2.4.5 immediately [1]. There is no known workaround for older versions; updating is the only complete mitigation [1].

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.