๐Ÿ” CVE Alert

CVE-2025-39545

UNKNOWN 0.0

WordPress REST API Authentication plugin <= 3.6.3 - Settings Change Vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3.

CWE CWE-862
Vendor miniorange
Product wordpress rest api authentication
Published Apr 16, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for miniorange wordpress rest api authentication

Be the first to know when new unknown vulnerabilities affecting miniorange wordpress rest api authentication are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

miniOrange / WordPress REST API Authentication
0 โ‰ค 3.6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/wp-rest-api-authentication/vulnerability/wordpress-wordpress-rest-api-authentication-3-6-3-settings-change-vulnerability?_s_id=cve

Credits

chuck | Patchstack Bug Bounty Program