VYPR
Medium severity5.3NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-58004

CVE-2025-58004

Description

Missing Authorization vulnerability in SmartDataSoft DriCub dricub-driving-school allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DriCub: from n/a through <= 2.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in the DriCub Driving School WordPress theme (≤2.9) allows unauthenticated attackers to exploit missing authorization checks.

The DriCub Driving School WordPress theme (versions up to and including 2.9) contains a missing authorization vulnerability. This broken access control issue stems from the lack of proper capability checks or nonce tokens in certain functions, allowing unprivileged users to perform actions intended for higher-privileged roles [1].

Attackers can exploit this vulnerability without authentication, as the access control security levels are incorrectly configured. The attack surface is broad because the theme is used on many WordPress sites, and the vulnerability can be leveraged in mass-exploit campaigns targeting thousands of websites simultaneously, regardless of their size or popularity [1].

Successful exploitation could allow an attacker to execute privileged actions, such as modifying site settings or accessing sensitive data, depending on the specific missing authorization. The CVSS v3 base score of 5.3 (Medium) reflects the potential for unauthorized access without requiring authentication [1].

As an immediate mitigation, users should update the DriCub theme to a patched version if available. If updating is not possible, it is recommended to contact the hosting provider or a web developer for assistance. The vulnerability is actively used in mass-exploit campaigns, so prompt action is advised [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.