VYPR
Medium severity4.3NVD Advisory· Published Oct 27, 2025· Updated Apr 27, 2026

CVE-2025-62938

CVE-2025-62938

Description

Missing Authorization vulnerability in Reoon Technology Reoon Email Verifier reoon-email-verifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reoon Email Verifier: from n/a through <= 2.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Reoon Email Verifier plugin ≤2.0.1 allows unauthenticated attackers to exploit broken access controls.

Vulnerability

Overview

The Reoon Email Verifier plugin for WordPress versions up to and including 2.0.1 contains a missing authorization vulnerability [1]. This issue stems from incorrectly configured access control security levels, meaning the plugin fails to properly verify user permissions before allowing certain actions [1].

Exploitation

An attacker can exploit this vulnerability without needing any authentication, as the broken access control allows unprivileged users to perform actions that should require higher privileges [1]. The attack surface is broad because the plugin is widely used, and this type of vulnerability is frequently targeted in mass-exploit campaigns against thousands of websites regardless of their size or popularity [1].

Impact

Successful exploitation could enable an attacker to access or modify sensitive data, or perform unauthorized administrative actions within the WordPress installation [1]. The CVSS v3 score of 4.3 (Medium) reflects the potential for partial compromise, though the vendor notes the severity is low and exploitation is unlikely [1].

Mitigation

The vulnerability is patched in version 2.1.1 of the plugin [1]. Users are strongly advised to update immediately. If updating is not possible, contacting a hosting provider or web developer for assistance is recommended [1]. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.