๐Ÿ” CVE Alert

CVE-2025-12350

MEDIUM 5.3

DominoKit <= 1.1.0 - Missing Authorization to Unauthenticated Settings Update

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update plugin settings.

CWE CWE-862
Vendor domiinodev
Product dominokit
Published Nov 4, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for domiinodev dominokit

Be the first to know when new medium vulnerabilities affecting domiinodev dominokit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

domiinodev / DominoKit
0 โ‰ค 1.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/1c8de019-4ec1-49fd-9b0b-c2b1b6908ba8?source=cve wordpress.org: https://wordpress.org/plugins/dominokit/

Credits

Abhirup Konwar