PT-2025-30734 · WordPress · Droip

Friderika Baranyai

·

Published

2025-07-25

·

Updated

2025-07-30

·

CVE-2025-5835

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Droip plugin for WordPress versions up to 2.2.0
Description The Droip plugin for WordPress is susceptible to unauthorized modification and access of data due to a missing capability check on the droip post apis() function. Authenticated attackers with Subscriber-level access or higher can perform actions through AJAX hooks to several functions, potentially leading to arbitrary post deletion, arbitrary post creation, post duplication, settings update, and user manipulation.
Recommendations Update the Droip plugin to a version newer than 2.2.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-5835

Affected Products

Droip