CVE-2025-24588Missing Authorization in Wordpress

Severity
3.5LOW
No vector
EPSS
0.2%
top 62.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 24
Latest updateJun 16

Description

Missing Authorization vulnerability in patreon Patreon WordPress patreon-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Patreon WordPress: from n/a through <= 1.9.1.

Affected Packages1 packages

CVEListV5patreon/patreon_wordpress1.9.1

🔴Vulnerability Details

3
Kernel
wifi: prevent A-MSDU attacks in mesh networks2025-06-16
CVEList
WordPress Patreon WordPress plugin <= 1.9.1 - Broken Access Control vulnerability2025-01-24
GHSA
GHSA-3v34-886r-p598: Missing Authorization vulnerability in Patreon Patreon WordPress allows Exploiting Incorrectly Configured Access Control Security Levels2025-01-24
CVE-2025-24588 — Missing Authorization in Wordpress | cvebase