CVE-2025-60088
Description
Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarIgnition: from n/a through <= 4.06.04.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WebinarIgnition plugin <=4.06.04 has missing authorization allowing unprivileged attackers to exploit incorrectly configured access controls.
Vulnerability
Overview The vulnerability is a Missing Authorization issue in the WebinarIgnition plugin by Saleswonder Team (Tobias). It affects versions from n/a through 4.06.04. The root cause is an incorrectly configured access control security level, meaning that certain functions do not properly enforce authorization, authentication, or nonce token checks [1].
Exploitation
This broken access control vulnerability can be exploited by unauthenticated or low-privilege attackers to perform higher-privileged actions without proper authorization. The attack surface is broad, as the plugin is used on thousands of WordPress websites, and the vulnerability is expected to be used in mass-exploit campaigns [1]. No special prerequisites beyond network access to the site are mentioned.
Impact
Successful exploitation allows an attacker to bypass access control restrictions and execute actions normally reserved for higher-privileged users. The CVSS v3 score is 6.5 (Medium), reflecting the moderate potential for harm [1].
Mitigation
The vendor has released version 4.06.05 which patches the vulnerability. Users are strongly advised to update immediately. For those unable to update, implementing a mitigation rule (such as those provided by Patchstack) can block attacks until the update is applied [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.