CVE-2025-64243
Description
Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Directory Pro plugin (<=2.5.6) allows attackers to exploit broken access controls, potentially leading to unauthorized actions.
Vulnerability
Overview
The Directory Pro plugin by e-plugins contains a missing authorization vulnerability (CVE-2025-64243) in versions up to 2.5.6. The plugin fails to properly validate user permissions when executing certain functions, allowing unauthenticated or low-privileged users to access capabilities reserved for higher-privileged roles. This issue stems from incorrect configuration of access control security levels [1].
Exploitation
Attackers can exploit this flaw by sending crafted requests to vulnerable endpoints without needing prior authentication. The vulnerability is particularly concerning because it is reportedly used in mass-exploit campaigns that target thousands of WordPress sites, regardless of their size or popularity [1]. No special prerequisites are required beyond network access to the target site.
Impact
Successful exploitation can enable an attacker to perform actions such as modifying directory listings, altering plugin settings, or gaining unintended privileges. The CVSS v3 base score of 4.3 (Medium) reflects the low complexity and limited confidentiality/integrity impact, but the lack of authentication requirements makes it attractive for automated attacks.
Mitigation
As the only effective mitigation, users must update the Directory Pro plugin to a patched version immediately. If an update is unavailable, users should contact their hosting provider or a web developer for assistance [1]. No workarounds are mentioned.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=2.5.6+ 1 more
- (no CPE)range: <=2.5.6
- (no CPE)range: <=2.5.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.