VYPR

Aapanel Wp Toolkit

by WordPress

CVEs (1)

  • CVE-2025-6813HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.00

    The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass all role checks and gain full admin privileges.