VYPR
Medium severity5.3NVD Advisory· Published Jul 16, 2025· Updated Apr 23, 2026

CVE-2025-48155

CVE-2025-48155

Description

Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Residential Address Detection: from n/a through <= 2.5.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Residential Address Detection plugin <=2.5.9 has missing authorization, allowing unprivileged attackers to access functions without proper ACLs.

The WordPress Residential Address Detection plugin versions from n/a through 2.5.9 lack proper authorization checks in certain functionality. This is a broken access control (BAC) vulnerability, meaning the plugin fails to verify that a user has the required privileges before executing an action [1].

An attacker with minimal privileges (e.g., subscriber or even an unauthenticated user if nonce checks are missing) can exploit this flaw by directly calling vulnerable endpoints. No special setup is needed beyond having any level of WordPress access or by sending crafted requests that bypass intended restrictions [1].

Successful exploitation allows an attacker to access functionality that should be constrained by Access Control Lists (ACLs), potentially leading to unauthorized modifications, data exposure, or other actions intended only for higher-privileged roles like administrators [1].

The plugin vendor has addressed this issue in version 2.5.10. Users are strongly advised to update immediately. For those unable to update, manual patching or contacting a hosting provider/web developer is recommended. The vulnerability is considered low severity by the vendor but could be used in mass-exploit campaigns targeting thousands of sites [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.