CVE-2025-60116

Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:themegoods:grand_conference:*:*:*:*:*:wordpress:*:*

History

23 Apr 2026, 15:34

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 5.4

01 Apr 2026, 17:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 8.8
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/grandconference-custom-post/vulnerability/wordpress-grand-conference-theme-custom-post-type-plugin-2-6-3-broken-access-control-vulnerability?_s_id=cve', 'tags': ['Third Party Advisory'], 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/grandconference-custom-post/vulnerability/wordpress-grand-conference-theme-custom-post-type-plugin-2-6-3-broken-access-control-vulnerability?_s_id=cve - Third Party Advisory
Summary (en) Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Grand Conference Theme Custom Post Type: from n/a through 2.6.3. (en) Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Conference Theme Custom Post Type: from n/a through < 2.6.4.

27 Jan 2026, 19:55

Type Values Removed Values Added
References () https://patchstack.com/database/wordpress/plugin/grandconference-custom-post/vulnerability/wordpress-grand-conference-theme-custom-post-type-plugin-2-6-3-broken-access-control-vulnerability?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/grandconference-custom-post/vulnerability/wordpress-grand-conference-theme-custom-post-type-plugin-2-6-3-broken-access-control-vulnerability?_s_id=cve - Third Party Advisory
First Time Themegoods
Themegoods grand Conference
CPE cpe:2.3:a:themegoods:grand_conference:*:*:*:*:*:wordpress:*:*

26 Sep 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-26 09:15

Updated : 2026-04-23 15:34


NVD link : CVE-2025-60116

Mitre link : CVE-2025-60116

CVE.ORG link : CVE-2025-60116


JSON object : View

Products Affected

themegoods

  • grand_conference
CWE
CWE-862

Missing Authorization