PT-2026-1595 · WordPress · Unify

Abhirup Konwar

·

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2025-13529

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Unify plugin for WordPress versions up to and including 3.4.9
Description The Unify plugin for WordPress is susceptible to unauthorized data modification because of a missing capability check on the 'init' action. This allows unauthenticated attackers to delete specific plugin options by manipulating the unify plugin downgrade parameter.
Recommendations Update the Unify plugin to a version newer than 3.4.9.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13529

Affected Products

Unify