PT-2025-29990 · WordPress · Aapanel Wp Toolkit

Kenneth Dunn

·

Published

2025-07-18

·

Updated

2026-03-17

·

CVE-2025-6813

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions aapanel WP Toolkit versions 1.0 through 1.1
Description The aapanel WP Toolkit plugin for WordPress is susceptible to privilege escalation due to missing authorization checks within the auto login() function. Authenticated attackers with Subscriber-level access or higher can bypass role checks and obtain full admin privileges.
Recommendations Update aapanel WP Toolkit to a version newer than 1.1.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-6813

Affected Products

Aapanel Wp Toolkit