VYPR
Medium severity4.3NVD Advisory· Published Nov 21, 2025· Updated Apr 27, 2026

CVE-2025-66087

CVE-2025-66087

Description

Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

PropertyHive plugin for WordPress <=2.1.12 has a missing authorization vulnerability allowing unauthenticated attackers to exploit incorrectly configured access control security levels.

Vulnerability

Overview

CVE-2025-66087 is a missing authorization vulnerability in the PropertyHive plugin for WordPress, affecting versions from n/a through 2.1.12. The issue stems from incorrectly configured access control security levels, which allows unauthenticated attackers to exploit the plugin's functions without proper permission checks [1].

Exploitation

An attacker can exploit this vulnerability by sending crafted requests to a WordPress site running a vulnerable version of PropertyHive. No authentication is required, and the attack can be performed remotely over the network. The vulnerability is classified as a low complexity and does not require user interaction, making it potentially exploitable in mass campaigns targeting thousands of websites [1].

Impact

Successful exploitation could allow an attacker to perform actions that should be restricted to higher-privileged users, such as modifying property listings or accessing sensitive data. The CVSS v3 base score is 4.3 (Medium), indicating a moderate severity with limited direct impact on confidentiality, integrity, or availability [1].

Mitigation

The vendor has released version 2.1.13 which addresses the vulnerability. Users are strongly advised to update immediately. For those unable to update, consulting a hosting provider or web developer is recommended. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.