VYPR
Medium severity5.3NVD Advisory· Published Dec 16, 2025· Updated Apr 27, 2026

CVE-2025-64249

CVE-2025-64249

Description

Missing Authorization vulnerability in WP-EXPERTS.IN Protect WP Admin protect-wp-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protect WP Admin: from n/a through <= 4.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Protect WP Admin plugin (≤4.1 allows unauthenticated attackers to bypass access controls, potentially exposing admin functions.

Vulnerability

Overview CVE-2025-64249 is a missing authorization vulnerability in the Protect WP Admin plugin for WordPress, affecting versions up to and including 4.1. The plugin fails to properly enforce access control security levels, allowing attackers to exploit incorrectly configured access controls [1].

Exploitation

This broken access control issue can be exploited without authentication, as the plugin does not perform adequate authorization checks on certain functions. Attackers can leverage this to perform actions that should require higher privileges, potentially targeting thousands of websites in mass-exploit campaigns [1].

Impact

Successful exploitation allows an unprivileged user to execute higher-privileged actions, such as accessing or modifying protected admin areas. The CVSS v3 score of 5.3 (Medium) reflects the potential for unauthorized access, though the vendor notes a low likelihood of exploitation [1].

Mitigation

The vulnerability is addressed in version 4.2 of the plugin. Users are strongly advised to update immediately. If updating is not possible, contacting a hosting provider or web developer for assistance is recommended. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.