VYPR
Medium severity5.3NVD Advisory· Published Sep 9, 2025· Updated Apr 23, 2026

CVE-2025-58980

CVE-2025-58980

Description

Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export WP Page to Static HTML/CSS: from n/a through <= 4.1.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Export WP Page to Static HTML/CSS plugin up to v4.1.0 allows unauthenticated access to administrative functions.

Vulnerability

Overview

The Export WP Page to Static HTML/CSS plugin for WordPress suffers from a missing authorization vulnerability (Broken Access Control) affecting versions from n/a through 4.1.0 [1]. This flaw allows an attacker to access functionality that should be restricted to higher-privileged users, as the plugin fails to properly enforce access controls on certain operations.

Exploitation

No authentication is required to exploit this vulnerability, making it accessible to any unauthenticated visitor. The attack can be carried out over the network without any special privileges or user interaction [1]. This low-complexity attack vector is particularly dangerous because it can be automated to target thousands of sites in mass-exploit campaigns.

Impact

A successful exploit permits an unauthenticated attacker to access functionality that is normally constrained to administrators, such as potentially modifying plugin settings or exporting sensitive data [1]. While the CVSS score of 5.3 indicates medium severity, the ease of exploitation raises the practical risk.

Mitigation

The vulnerability has been addressed in version 4.2.0 of the plugin. Users are strongly advised to update immediately. If updating is not possible, administrators should consider disabling the plugin or applying additional access controls via web application firewall rules until an update can be applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.