CVE-2025-60143
Description
Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netgsm: from n/a through <= 2.9.69.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Netgsm WordPress plugin versions up to 2.9.69 contain a missing authorization vulnerability allowing unprivileged attackers to exploit incorrectly configured access controls.
Vulnerability
Overview The Netgsm WordPress plugin (netgsm) versions from n/a through 2.9.69 suffer from a Missing Authorization vulnerability [1]. This flaw stems from incorrectly configured access control security levels, meaning the plugin fails to properly verify that a user has the necessary privileges before allowing certain actions [1]. The issue is classified as a Broken Access Control vulnerability, which typically involves missing authorization, authentication, or nonce token checks in a function that could allow an unprivileged user to execute a higher-privileged action [1].
Exploitation
Context Attackers can exploit this vulnerability without requiring any special privileges, as the access control checks are missing or improperly implemented [1]. The vulnerability is noted to be used in mass-exploit campaigns, where attackers target thousands of websites simultaneously regardless of their size or popularity [1]. The CVSS v3 base score is 4.3 (Medium), reflecting the potential for unauthorized access but not full system compromise [1].
Impact and
Mitigation Successful exploitation could allow an attacker to perform actions that should be restricted to higher-privileged users, potentially leading to unauthorized data exposure or modification of sensitive data [1]. The vendor has not yet released a patched version beyond 2.9.69, so immediate action is recommended: update the plugin if a newer version becomes available, or contact your hosting provider or web developer for assistance [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.