VYPR
Medium severity4.3NVD Advisory· Published Dec 31, 2025· Updated Apr 23, 2026

CVE-2025-63004

CVE-2025-63004

Description

Missing Authorization vulnerability in Skynet Technologies USA LLC All in One Accessibility all-in-one-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All in One Accessibility: from n/a through <= 1.15.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in All in One Accessibility plugin (≤1.15) allows unauthenticated attackers to exploit broken access controls, enabling unauthorized actions.

The All in One Accessibility plugin for WordPress, versions 1.15 and earlier, contains a missing authorization vulnerability. The root cause is a broken access control issue where certain functions lack proper authentication or nonce token checks, allowing unprivileged users to execute higher-privileged actions [1].

Exploitation requires no authentication, as the vulnerability is exposed to unauthenticated attackers. The attack surface is broad, as the plugin is widely used, and the issue can be triggered via direct requests to vulnerable endpoints [1].

An attacker can exploit this to perform unauthorized actions, such as modifying settings or accessing restricted functionality, without needing any privileges. This could lead to partial compromise of the site's accessibility features [1].

The vulnerability is patched in version 1.16. Users are strongly advised to update immediately. For those unable to update, contacting a hosting provider or web developer is recommended. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.