CVE-2025-6003

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3 versions of the plugin. This makes it possible for unauthenticated attackers to extract sensitive data including site content that has been restricted to certain users and/or roles.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) El complemento WordPress Single Sign-On (SSO) para WordPress es vulnerable a accesos no autorizados debido a una comprobación de capacidad mal configurada en una función en todas las versiones del complemento, hasta la versión *.5.3 incluida. Esto permite a atacantes no autenticados extraer datos confidenciales, incluido contenido del sitio restringido a ciertos usuarios o roles.

12 Jun 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-12 09:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-6003

Mitre link : CVE-2025-6003

CVE.ORG link : CVE-2025-6003


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization