VYPR
Medium severity6.5NVD Advisory· Published Dec 18, 2025· Updated Apr 27, 2026

CVE-2025-64273

CVE-2025-64273

Description

Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-official allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email marketing for WordPress by GetResponse Official: from n/a through <= 1.5.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in GetResponse Email marketing plugin for WordPress (<=1.5.3) allows unauthenticated attackers to exploit broken access controls.

The GetResponse Email marketing for WordPress plugin (getresponse-official) contains a missing authorization vulnerability in versions up to and including 1.5.3. The issue stems from incorrectly configured access control security levels, which allow unprivileged users to execute actions that should require higher privileges [1].

The vulnerability can be exploited over the network without authentication, and does not require user interaction. Attackers can target thousands of websites at once in mass-exploit campaigns, as the flaw affects any site running the vulnerable plugin version [1]. The attack surface is broad because the plugin is widely deployed for email marketing.

Successful exploitation enables an attacker to perform actions that should be restricted to higher-privileged users, such as modifying plugin settings or accessing sensitive data, depending on the specific missing authorization check [1]. The CVSS v3.1 score is 6.5 (Medium), reflecting a significant but not critical risk.

The vulnerability is patched in version 1.5.4 of the plugin. Immediate update to version 1.5.4 or later is strongly recommended. For sites unable to update immediately, hosting providers or web developers should apply mitigations such as Patchstack's rules to block attacks until the update can be performed [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.