CVE-2025-67562
Description
Missing Authorization vulnerability in WebCodingPlace Image Caption Hover Pro image-caption-hover-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Caption Hover Pro: from n/a through < 20.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing Authorization in Image Caption Hover Pro up to version 20.0 allows unauthenticated attackers to exploit incorrectly configured access controls.
The WordPress plugin Image Caption Hover Pro suffers from a missing authorization vulnerability, classified as a Broken Access Control issue. The plugin fails to properly enforce access control checks on certain functions, allowing attackers to bypass intended restrictions. This vulnerability affects all versions from n/a through before 20.0 [1].
The attack surface is broad: an unauthenticated attacker can exploit the missing authorization checks without needing any special privileges or authentication. The vulnerability can be used in mass-exploit campaigns, targeting thousands of websites regardless of their size or popularity. No user interaction is required for exploitation [1].
Successful exploitation could allow an attacker to perform unauthorized actions within the plugin, such as modifying settings or data that should be restricted. The CVSS v3 base score is 5.4 (Medium), indicating a moderate impact on confidentiality, integrity, and availability. Although the severity is rated low by the vendor, the ease of mass exploitation increases the real-world risk [1].
The vulnerability has been patched in version 20.0. Users are strongly advised to update to this version or later. Patchstack users can enable auto-updates for vulnerable plugins. If updating is not immediately possible, it is recommended to contact a hosting provider or web developer for assistance [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: < 20.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.