๐Ÿ” CVE Alert

CVE-2025-22695

MEDIUM 4.3

WordPress Nirweb support plugin <= 3.0.3 - Broken Access Control vulnerability

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support nirweb-support.This issue affects Nirweb support: from n/a through <= 3.0.3.

CWE CWE-639
Vendor nirwp team
Product nirweb support
Published Feb 3, 2025
Last Updated Apr 28, 2026
Stay Ahead of the Next One

Get instant alerts for nirwp team nirweb support

Be the first to know when new medium vulnerabilities affecting nirwp team nirweb support are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

NirWp Team / Nirweb support
0 โ‰ค 3.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/nirweb-support/vulnerability/wordpress-nirweb-support-plugin-3-0-3-broken-access-control-vulnerability?_s_id=cve

Credits

Fariq Fadillah Gusti Insani | Patchstack Bug Bounty Program