PT-2025-3932 · WordPress · The Buzz Club – Night Club

Lucio Sá

·

Published

2025-01-18

·

Updated

2025-01-18

·

CVE-2025-0515

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme versions up to, and including, 2.0.4
Description The issue allows unauthorized modification of data, potentially leading to a denial of service. This is due to a missing capability check on the cmsmasters hide admin notice function. Authenticated attackers with Subscriber-level access and above can update option values to 'hide' on the WordPress site, creating an error or denying service to legitimate users.
Recommendations For versions up to, and including, 2.0.4, consider disabling the cmsmasters hide admin notice function until a patch is available to prevent unauthorized data modification. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-0515

Affected Products

The Buzz Club – Night Club