VYPR
Medium severity4.3NVD Advisory· Published Feb 3, 2026· Updated Apr 15, 2026

CVE-2026-25011

CVE-2026-25011

Description

Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.41.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The WP Custom Admin Interface plugin <=7.41 for WordPress has a missing authorization check, allowing unprivileged users to exploit access controls.

The WP Custom Admin Interface plugin for WordPress, up to and including version 7.41, is vulnerable to a missing authorization issue (CVE-2026-25011). This flaw allows exploiting incorrectly configured access control security levels due to a lack of proper authorization checks in one or more functions [1].

An attacker who is an unprivileged user (e.g., subscriber or contributor) can exploit this broken access control to execute higher-privileged actions without proper authentication or nonce token verification. The vulnerability arises from missing authorization, authentication, or nonce token checks in the plugin's code [1].

The impact is that an attacker may be able to perform actions that should require higher privileges, potentially compromising the site. The severity is medium (CVSS 3.1 base score 4.3). While Patchstack notes the vulnerability has low severity and is unlikely to be exploited, it is important to address as part of defense-in-depth [1].

Mitigation is available. The vulnerability has been fixed in version 7.42 of the plugin. Users are strongly advised to update immediately. Alternatively, Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.