CVE-2025-58980
Description
Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export WP Page to Static HTML/CSS: from n/a through <= 4.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Export WP Page to Static HTML/CSS plugin up to v4.1.0 allows unauthenticated access to administrative functions.
Vulnerability
Overview
The Export WP Page to Static HTML/CSS plugin for WordPress suffers from a missing authorization vulnerability (Broken Access Control) affecting versions from n/a through 4.1.0 [1]. This flaw allows an attacker to access functionality that should be restricted to higher-privileged users, as the plugin fails to properly enforce access controls on certain operations.
Exploitation
No authentication is required to exploit this vulnerability, making it accessible to any unauthenticated visitor. The attack can be carried out over the network without any special privileges or user interaction [1]. This low-complexity attack vector is particularly dangerous because it can be automated to target thousands of sites in mass-exploit campaigns.
Impact
A successful exploit permits an unauthenticated attacker to access functionality that is normally constrained to administrators, such as potentially modifying plugin settings or exporting sensitive data [1]. While the CVSS score of 5.3 indicates medium severity, the ease of exploitation raises the practical risk.
Mitigation
The vulnerability has been addressed in version 4.2.0 of the plugin. Users are strongly advised to update immediately. If updating is not possible, administrators should consider disabling the plugin or applying additional access controls via web application firewall rules until an update can be applied [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=4.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.