PT-2025-19872 · WordPress · Pgs Core

István Márton

·

Published

2025-05-06

·

Updated

2025-05-07

·

CVE-2025-0856

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PGS Core plugin for WordPress versions prior to 5.8.1
Description The issue is related to a missing capability check on multiple functions, which allows unauthorized access, modification, and potential loss of data. This could enable unauthenticated attackers to add, modify, or alter plugin options.
Recommendations For versions prior to 5.8.1, update to version 5.8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functions to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-0856

Affected Products

Pgs Core