🔐 CVE Alert

CVE-2025-58711

MEDIUM 5.3

WordPress Blog Designer PRO plugin <= 3.4.8 - Broken Access Control vulnerability

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blog Designer PRO: from n/a through <= 3.4.8.

CWE CWE-862
Vendor solwin
Product blog designer pro
Published Oct 29, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for solwin blog designer pro

Be the first to know when new medium vulnerabilities affecting solwin blog designer pro are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

solwin / Blog Designer PRO
0 ≤ 3.4.8

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/blog-designer-pro/vulnerability/wordpress-blog-designer-pro-plugin-3-4-8-broken-access-control-vulnerability?_s_id=cve

Credits

Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program