PT-2025-46265 · WordPress · Shelf Planner

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-11894

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shelf Planner plugin for WordPress versions prior to 2.7.1
Description The Shelf Planner plugin for WordPress is susceptible to unauthorized data modification. This is due to a lack of proper capability checks on several REST API endpoints. An unauthenticated attacker can modify plugin settings, including the ServerKey and LicenseKey. The affected API endpoints lack the necessary authorization controls, allowing unauthorized access and modification of sensitive data.
Recommendations Update the Shelf Planner plugin to version 2.7.1 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-11894

Affected Products

Shelf Planner