VYPR
Medium severity6.5NVD Advisory· Published Dec 18, 2025· Updated Apr 15, 2026

CVE-2025-60088

CVE-2025-60088

Description

Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarIgnition: from n/a through <= 4.06.04.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

WebinarIgnition plugin <=4.06.04 has missing authorization allowing unprivileged attackers to exploit incorrectly configured access controls.

Vulnerability

Overview The vulnerability is a Missing Authorization issue in the WebinarIgnition plugin by Saleswonder Team (Tobias). It affects versions from n/a through 4.06.04. The root cause is an incorrectly configured access control security level, meaning that certain functions do not properly enforce authorization, authentication, or nonce token checks [1].

Exploitation

This broken access control vulnerability can be exploited by unauthenticated or low-privilege attackers to perform higher-privileged actions without proper authorization. The attack surface is broad, as the plugin is used on thousands of WordPress websites, and the vulnerability is expected to be used in mass-exploit campaigns [1]. No special prerequisites beyond network access to the site are mentioned.

Impact

Successful exploitation allows an attacker to bypass access control restrictions and execute actions normally reserved for higher-privileged users. The CVSS v3 score is 6.5 (Medium), reflecting the moderate potential for harm [1].

Mitigation

The vendor has released version 4.06.05 which patches the vulnerability. Users are strongly advised to update immediately. For those unable to update, implementing a mitigation rule (such as those provided by Patchstack) can block attacks until the update is applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.