CVE-2025-57991
Description
Missing Authorization vulnerability in Clariti Clariti clariti allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clariti: from n/a through <= 1.2.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Clariti WordPress plugin (≤1.2.1) allows unprivileged users to exploit incorrectly configured access controls.
Vulnerability
Overview CVE-2025-57991 is a missing authorization vulnerability in the Clariti WordPress plugin, affecting versions from n/a through 1.2.1. The root cause is an incorrectly configured access control security level, which fails to properly enforce authorization checks for certain functions. This allows an attacker to exploit broken access control mechanisms without requiring elevated privileges.
Exploitation
Exploitation
Details from Patchstack indicate this is a broken access control issue, meaning the plugin lacks proper authorization, authentication, or nonce token checks in a function that could lead to an unprivileged user executing a higher privileged action [1].
Exploitation and
Impact An attacker can exploit this vulnerability by sending crafted requests to the vulnerable plugin endpoints, bypassing intended access restrictions. The attack does not require authentication, as the missing authorization check allows any unauthenticated user to perform actions that should be restricted to higher-privileged roles. The CVSS v3 score of 5.4 (Medium) reflects the potential for unauthorized access to sensitive functionality.
Mitigation
The vulnerability has been addressed in version 1.2.2 of the Clariti plugin. Users are strongly advised to update to this version or later. Patchstack users can enable auto-update for vulnerable plugins. For those unable to update immediately, consulting a hosting provider or web developer is recommended [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.