
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-3702 is a Missing Authorization (Broken Access Control) vulnerability in the Melapress File Monitor WordPress plugin that allows low-privileged authenticated attackers to perform actions beyond their intended privilege level. It affects all versions of the plugin prior to 2.2.0. The vulnerability was reported by researcher Mika on November 20, 2024, and publicly disclosed on July 3, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium) (Patchstack, Red Hat).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning one or more plugin functions lack proper authorization, authentication, or nonce token checks before executing privileged operations (Patchstack). This falls under OWASP Top 10 category A1: Broken Access Control. An attacker with at minimum Subscriber-level access to a WordPress site can exploit this flaw over the network without any user interaction, triggering higher-privileged actions within the plugin. The attack complexity is low, requiring only valid low-privilege credentials on the target WordPress installation.
Successful exploitation allows a low-privileged authenticated user (e.g., a Subscriber) to perform unauthorized actions within the Melapress File Monitor plugin, resulting in limited integrity and availability impacts. Specifically, the CVSS assessment indicates low integrity impact and low availability impact, with no confidentiality impact. In practice, this could allow an attacker to tamper with file monitoring configurations, disable monitoring, or disrupt the plugin's functionality, potentially undermining the site's file integrity monitoring capabilities (Patchstack, Red Hat).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported for CVE-2025-3702 as of the disclosure date. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term (Feedly). However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity, and has issued a virtual patch (mitigation rule) to block attacks for its users (Patchstack). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
wp-content/plugins/website-file-changes-monitor/readme.txt.wp-admin/admin-ajax.php with the appropriate action parameter) to invoke a privileged plugin function without the required authorization checks.wp-admin/admin-ajax.php with Melapress File Monitor-specific action parameters originating from low-privilege user sessions.wp_options entries prefixed with wfcm_ or similar plugin-specific keys) not initiated by an administrator.The vendor Melapress has released version 2.2.0 of the Melapress File Monitor plugin, which patches this vulnerability. All users should update to version 2.2.0 or later immediately via the WordPress plugin dashboard or by downloading from the WordPress plugin repository (Patchstack). As a temporary workaround for sites unable to update immediately, Patchstack users can rely on the virtual patch (mitigation rule) issued by Patchstack to block exploitation attempts. Site administrators should also review user accounts and remove any unnecessary Subscriber-level or other low-privilege accounts to reduce the attack surface.
The vulnerability was assigned and disclosed by Patchstack as part of their Active Vulnerability Disclosure Program (VDP), with researcher Mika credited for the discovery. Patchstack flagged the vulnerability class as commonly leveraged in mass-exploit campaigns against WordPress sites. The disclosure received routine coverage from vulnerability aggregators and security feeds including Red Hat CVE database, CIRCL, VulnDB, and CVEFeed, but no notable independent researcher commentary or significant social media discussion has been identified beyond standard automated security feeds (Patchstack, Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."