PT-2025-43594 · WordPress · Supervisor Plugin

Published

2025-10-24

·

Updated

2025-10-24

·

CVE-2025-11887

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress Supervisor Plugin versions up to and including 1.3.2
Description The Supervisor plugin for WordPress is susceptible to unauthorized data modification. This is due to a missing capability check in multiple AJAX functions. Authenticated attackers with Subscriber-level access or higher can modify various plugin settings. The affected API endpoints are not specified. The vulnerable parameters or variables are not specified. The vulnerable function is not specified.
Recommendations Update the Supervisor plugin to a version later than 1.3.2.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-11887

Affected Products

Supervisor Plugin