PT-2025-30517 · WordPress · Social Streams

Published

2025-07-23

·

Updated

2025-08-18

·

CVE-2025-7722

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Social Streams plugin for WordPress versions up to and including 1.0.1
Description The Social Streams plugin for WordPress does not properly validate a user's identity before updating user meta information via the update user meta() function. This allows authenticated attackers with Subscriber-level access or higher to modify their user type to administrator.
Recommendations Update the Social Streams plugin to a version later than 1.0.1.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-7722

Affected Products

Social Streams