VYPR
Medium severity5.4NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-67562

CVE-2025-67562

Description

Missing Authorization vulnerability in WebCodingPlace Image Caption Hover Pro image-caption-hover-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Caption Hover Pro: from n/a through < 20.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing Authorization in Image Caption Hover Pro up to version 20.0 allows unauthenticated attackers to exploit incorrectly configured access controls.

The WordPress plugin Image Caption Hover Pro suffers from a missing authorization vulnerability, classified as a Broken Access Control issue. The plugin fails to properly enforce access control checks on certain functions, allowing attackers to bypass intended restrictions. This vulnerability affects all versions from n/a through before 20.0 [1].

The attack surface is broad: an unauthenticated attacker can exploit the missing authorization checks without needing any special privileges or authentication. The vulnerability can be used in mass-exploit campaigns, targeting thousands of websites regardless of their size or popularity. No user interaction is required for exploitation [1].

Successful exploitation could allow an attacker to perform unauthorized actions within the plugin, such as modifying settings or data that should be restricted. The CVSS v3 base score is 5.4 (Medium), indicating a moderate impact on confidentiality, integrity, and availability. Although the severity is rated low by the vendor, the ease of mass exploitation increases the real-world risk [1].

The vulnerability has been patched in version 20.0. Users are strongly advised to update to this version or later. Patchstack users can enable auto-updates for vulnerable plugins. If updating is not immediately possible, it is recommended to contact a hosting provider or web developer for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.