VYPR
Medium severity5.5NVD Advisory· Published Oct 27, 2025· Updated Apr 27, 2026

CVE-2025-62965

CVE-2025-62965

Description

Missing Authorization vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin Management Xtended : from n/a through <= 2.5.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Admin Management Xtended <=2.5.1 has a missing authorization vulnerability allowing unprivileged users to exploit incorrectly configured access controls.

The Admin Management Xtended WordPress plugin, versions 2.5.1 and earlier, contains a missing authorization vulnerability. The root cause is an incorrectly configured access control security level, which fails to properly verify user privileges before granting access to certain administrative functions [1].

This vulnerability can be exploited by any unauthenticated or low-privileged user who can reach the affected plugin endpoints. No special authentication or network position is required beyond being able to send requests to the WordPress site. The attack surface is broad, as the plugin is used on many sites and the flaw can be triggered remotely [1].

An attacker exploiting this missing authorization can perform actions that should be restricted to higher-privileged users, such as administrators. This could lead to unauthorized configuration changes, data exposure, or other administrative-level operations, depending on the specific functions exposed by the plugin [1].

The vendor has released version 2.5.2 which patches the vulnerability. Users are strongly advised to update immediately. For those unable to update, contacting a hosting provider or web developer for assistance is recommended. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.