PT-2025-43591 · WordPress · Check Plagiarism

Published

2025-10-24

·

Updated

2025-10-24

·

CVE-2025-11172

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Check Plagiarism plugin for WordPress versions up to and including 2.0
Description The Check Plagiarism plugin for WordPress has an issue where data can be modified without authorization. This is due to a missing capability check within the chk plag mine plugin wpse10500 admin action() function. Authenticated attackers with Subscriber-level access or higher can update the API key. The vulnerable parameter is the API key.
Recommendations Update to a version beyond 2.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-11172

Affected Products

Check Plagiarism