VYPR
Medium severity4.3NVD Advisory· Published Dec 16, 2025· Updated Apr 27, 2026

CVE-2025-64243

CVE-2025-64243

Description

Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Directory Pro plugin (<=2.5.6) allows attackers to exploit broken access controls, potentially leading to unauthorized actions.

Vulnerability

Overview

The Directory Pro plugin by e-plugins contains a missing authorization vulnerability (CVE-2025-64243) in versions up to 2.5.6. The plugin fails to properly validate user permissions when executing certain functions, allowing unauthenticated or low-privileged users to access capabilities reserved for higher-privileged roles. This issue stems from incorrect configuration of access control security levels [1].

Exploitation

Attackers can exploit this flaw by sending crafted requests to vulnerable endpoints without needing prior authentication. The vulnerability is particularly concerning because it is reportedly used in mass-exploit campaigns that target thousands of WordPress sites, regardless of their size or popularity [1]. No special prerequisites are required beyond network access to the target site.

Impact

Successful exploitation can enable an attacker to perform actions such as modifying directory listings, altering plugin settings, or gaining unintended privileges. The CVSS v3 base score of 4.3 (Medium) reflects the low complexity and limited confidentiality/integrity impact, but the lack of authentication requirements makes it attractive for automated attacks.

Mitigation

As the only effective mitigation, users must update the Directory Pro plugin to a patched version immediately. If an update is unavailable, users should contact their hosting provider or a web developer for assistance [1]. No workarounds are mentioned.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.