VYPR
Medium severity5.3NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-58000

CVE-2025-58000

Description

Missing Authorization vulnerability in memberful Memberful - Membership Plugin memberful-wp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberful - Membership Plugin: from n/a through <= 1.75.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Memberful WordPress plugin up to 1.75.0 allows unprivileged attackers to access restricted functionality.

Vulnerability

The Memberful - Membership Plugin for WordPress (versions 1.75.0 and below) contains a missing authorization vulnerability. The plugin fails to properly enforce access controls on certain functions, allowing users without proper privileges to access functionality that should be restricted to higher-level roles [1].

Exploitation

An attacker does not need authentication to exploit this issue; they can simply send crafted requests to the vulnerable endpoints. This type of broken access control is commonly targeted in mass-exploit campaigns, where attackers automate attacks against thousands of sites simultaneously [1].

Impact

Successful exploitation enables an attacker to perform actions reserved for authorized users, such as modifying plugin settings or accessing sensitive data. The exact impact depends on the unprotected functionality, but it can lead to site compromise or privilege escalation.

Mitigation

The vulnerability has been addressed in version 1.76.0 of the plugin. Users are strongly advised to update immediately. Although the severity is considered low and exploitation unlikely, the potential for mass exploitation warrants prompt action. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.