PT-2025-44947 · Domiinodev · Dominokit

Abhirup Konwar

·

Published

2025-11-04

·

Updated

2025-11-04

·

CVE-2025-12350

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp ajax nopriv dominokit option admin action AJAX endpoint in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update plugin settings.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12350

Affected Products

Dominokit