VYPR
Medium severity4.3NVD Advisory· Published Jul 16, 2025· Updated Apr 23, 2026

CVE-2025-54018

CVE-2025-54018

Description

Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners cm-pop-up-banners allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM Pop-Up banners: from n/a through <= 1.8.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in CM Pop-Up banners plugin (versions ≤1.8.4) allows unauthenticated attackers to exploit misconfigured access controls, enabling unauthorized actions.

Vulnerability

Overview The CM Pop-Up banners plugin for WordPress (versions through 1.8.4) contains a missing authorization vulnerability. The issue stems from incorrect access control security levels, allowing exploitation of broken access controls. This is classified as a Missing Authorization vulnerability (CWE-862). [1]

Exploitation

Method An attacker can exploit this vulnerability without authentication by sending crafted requests to the plugin. The lack of proper capability checks or nonce tokens means unprivileged users can execute actions that should require higher privileges. The vulnerability is present in all versions up to and including 1.8.4. [1]

Impact

Successful exploitation could allow an unprivileged attacker to perform unauthorized actions within the WordPress installation, such as modifying plugin settings or accessing restricted data. While the CVSS score is 4.3 (Medium), the vendor notes this is a low-severity impact and unlikely to be exploited in typical cases, though mass-exploit campaigns have been observed for similar vulnerabilities. [1]

Mitigation

The vulnerability has been patched in version 1.8.5. Users are strongly advised to update immediately. For Patchstack users, auto-updates can be enabled for vulnerable plugins. If updating is not possible, consulting with a hosting provider or web developer is recommended. [1]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.