PT-2025-52218 · WordPress · Sweet Energy Efficiency

Paolo Tresso

·

Published

2025-12-18

·

Updated

2025-12-18

·

CVE-2025-14618

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sweet Energy Efficiency plugin for WordPress versions through 1.0.6
Description The Sweet Energy Efficiency plugin for WordPress is susceptible to unauthorized access, modification, and data loss. This is due to a missing capability check on the sweet energy efficiency action AJAX handler. Authenticated attackers with subscriber-level access or higher can read, modify, and delete arbitrary graphs.
Recommendations Update the Sweet Energy Efficiency plugin to a version beyond 1.0.6.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14618

Affected Products

Sweet Energy Efficiency