CVE-2025-60128
Description
Missing Authorization vulnerability in WP Delicious Delisho dr-widgets-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Delisho: from n/a through <= 1.1.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Delisho dr-widgets-blocks plugin <=1.1.3 has a missing authorization vulnerability allowing low-privilege users to exploit incorrectly configured access controls.
The Delisho dr-widgets-blocks plugin for WordPress, versions 1.1.3 and earlier, suffers from a missing authorization vulnerability. The root cause is an incorrectly configured access control security level, meaning that certain functions do not properly verify user permissions before executing privileged actions [1].
Attackers can exploit this flaw without needing elevated privileges, as the missing authorization check allows unprivileged users to trigger higher-privileged actions. The vulnerability can be leveraged in mass exploitation campaigns targeting thousands of websites, regardless of site size or popularity [1].
The impact is that an attacker can bypass intended access restrictions, potentially leading to unauthorized data manipulation or site compromise. The vulnerability is classified with a CVSS v3 score of 4.3 (Medium) and is considered a low-severity issue but is realistic to exploit due to the widespread use of the plugin [1].
Mitigation is straightforward: users must update to version 1.1.4 or later. Patchstack users can enable auto-updates for vulnerable plugins. If immediate update is not feasible, contacting a hosting provider or developer is recommended as a temporary measure [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.1.3
- Range: <=1.1.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.