As immediate action, update the affected plugin. If you're unable to do so, ask your hosting provider or web developer for help.
While this vulnerability can be initiated by the role shown in "Required Privilege", successful exploitation requires a privileged user to perform an action — such as clicking a malicious link, visiting a crafted page, or submitting a form.
Logged-in users can be tricked into performing actions they didn't intend, like changing passwords or making purchases.
CVSS score is a way to evaluate and rank reported vulnerabilities in a standardized and repeatable way but which is not ideal for WordPress.
This security issue has a low severity impact and is unlikely to be exploited.
26 Mar, 2025
Early warning sent out to Patchstack customers
16 May, 2025
Published by Patchstack
16 May, 2025