VYPR
Medium severity5.3NVD Advisory· Published Oct 27, 2025· Updated Apr 27, 2026

CVE-2025-62944

CVE-2025-62944

Description

Missing Authorization vulnerability in Mark O'Donnell MSTW CSV EXPORTER mstw-csv-exporter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MSTW CSV EXPORTER: from n/a through <= 1.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The MSTW CSV EXPORTER plugin for WordPress (≤1.4) is vulnerable to broken access control, allowing unauthenticated exploitation of missing authorization.

The MSTW CSV EXPORTER plugin for WordPress, developed by Mark O'Donnell, is vulnerable to a broken access control issue in versions up to and including 1.4. The vulnerability stems from missing authorization checks, meaning that the plugin fails to properly verify if a user has the necessary permissions before executing certain functions. This is classified as a Missing Authorization vulnerability (CWE-862) and can be exploited to perform actions that should require higher privileges.

Attackers can exploit this vulnerability without needing to authenticate themselves. The attack surface is remote, and no special network position is required beyond typical internet access. The broken access control allows an unprivileged actor to potentially access or modify CSV export functionality, bypassing security levels that should restrict such operations. The vulnerability is listed in the Patchstack database and is noted to be used in mass-exploit campaigns targeting thousands of websites [1].

The primary impact is the ability to exploit incorrectly configured access control security levels, potentially leading to unauthorized data export or manipulation. The CVSS v3 score is 5.3 (Medium), reflecting the moderate severity but wide reach of the issue. The advisory recommends immediate updating of the plugin to a patched version. If updating is not possible, users should contact their hosting provider or web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.