VYPR
Medium severity4.3NVD Advisory· Published Sep 26, 2025· Updated Apr 28, 2026

CVE-2025-60143

CVE-2025-60143

Description

Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netgsm: from n/a through <= 2.9.69.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Netgsm WordPress plugin versions up to 2.9.69 contain a missing authorization vulnerability allowing unprivileged attackers to exploit incorrectly configured access controls.

Vulnerability

Overview The Netgsm WordPress plugin (netgsm) versions from n/a through 2.9.69 suffer from a Missing Authorization vulnerability [1]. This flaw stems from incorrectly configured access control security levels, meaning the plugin fails to properly verify that a user has the necessary privileges before allowing certain actions [1]. The issue is classified as a Broken Access Control vulnerability, which typically involves missing authorization, authentication, or nonce token checks in a function that could allow an unprivileged user to execute a higher-privileged action [1].

Exploitation

Context Attackers can exploit this vulnerability without requiring any special privileges, as the access control checks are missing or improperly implemented [1]. The vulnerability is noted to be used in mass-exploit campaigns, where attackers target thousands of websites simultaneously regardless of their size or popularity [1]. The CVSS v3 base score is 4.3 (Medium), reflecting the potential for unauthorized access but not full system compromise [1].

Impact and

Mitigation Successful exploitation could allow an attacker to perform actions that should be restricted to higher-privileged users, potentially leading to unauthorized data exposure or modification of sensitive data [1]. The vendor has not yet released a patched version beyond 2.9.69, so immediate action is recommended: update the plugin if a newer version becomes available, or contact your hosting provider or web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.