VYPR
Medium severity5.3NVD Advisory· Published Sep 26, 2025· Updated Apr 23, 2026

CVE-2025-58919

CVE-2025-58919

Description

Missing Authorization vulnerability in guihom Wide Banner wide-banner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wide Banner: from n/a through <= 1.0.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Wide Banner plugin (≤1.0.4) allows unauthenticated attackers to exploit incorrectly configured access controls.

Vulnerability

Overview

The Wide Banner WordPress plugin, versions up to and including 1.0.4, contains a missing authorization vulnerability. This flaw stems from incorrectly configured access control security levels, allowing unprivileged users to perform actions that should require higher privileges [1].

Exploitation

Attackers can exploit this broken access control issue without needing authentication. The vulnerability is particularly dangerous because it can be leveraged in mass-exploit campaigns targeting thousands of websites, regardless of their size or popularity [1]. No special network position is required beyond standard internet access to the WordPress sites running the vulnerable plugin.

Impact

Successful exploitation allows an attacker to execute higher-privileged actions that should be restricted. This could lead to unauthorized modification of plugin settings or content, potentially compromising the site's integrity and security [1].

Mitigation

The vendor has not released a patched version beyond 1.0.4. Immediate action is recommended: update the plugin if a newer version becomes available, or disable it until a fix is released. Site administrators unable to update should consult their hosting provider or web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.