
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49041 is a Missing Authorization (Broken Access Control) vulnerability in the "Get Cash" WordPress plugin developed by The African Boss. It affects all versions up to and including 3.2.3, allowing unauthenticated attackers to exploit incorrectly configured access control security levels. The vulnerability was reported on September 30, 2025, and publicly disclosed on December 1, 2025, by Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization, authentication, or nonce token checks on one or more functions. This allows an unauthenticated remote attacker to invoke privileged actions that should be restricted to higher-privilege users. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity, making it straightforward to exploit. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows unauthenticated attackers to perform unauthorized actions on affected WordPress sites, resulting in low integrity and low availability impacts with no direct confidentiality impact. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity. The scope is limited to the affected WordPress installation, but unauthorized modification of plugin functionality or site data could facilitate further compromise (Patchstack).
No official patch is currently available for this vulnerability, leaving all sites running Get Cash version 3.2.3 or earlier exposed. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the wild, though Patchstack assesses it as expected to be exploited given its unauthenticated nature and suitability for mass-exploit campaigns. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (Patchstack, Feedly).
As of the disclosure date, no official patch from the plugin developer (The African Boss) is available. The primary recommended action is to deactivate and remove the Get Cash plugin until an official fix is released. Patchstack has issued a virtual patching/mitigation rule for its subscribers that blocks both legitimate and illegitimate requests to the vulnerable functionality as a temporary protective measure. Site administrators unable to remove the plugin should consult their hosting provider or web developer for assistance (Patchstack).
Patchstack, which coordinated the disclosure after the vulnerability was reported by researcher "Rooting" on September 30, 2025, has flagged this as a medium-priority issue expected to be leveraged in mass-exploit campaigns. No significant vendor statements, broader media coverage, or notable community commentary beyond the Patchstack advisory have been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."