CVE-2025-49041: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-49041 is a Missing Authorization (Broken Access Control) vulnerability in the "Get Cash" WordPress plugin developed by The African Boss. It affects all versions up to and including 3.2.3, allowing unauthenticated attackers to exploit incorrectly configured access control security levels. The vulnerability was reported on September 30, 2025, and publicly disclosed on December 1, 2025, by Patchstack. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization, authentication, or nonce token checks on one or more functions. This allows an unauthenticated remote attacker to invoke privileged actions that should be restricted to higher-privilege users. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity, making it straightforward to exploit. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows unauthenticated attackers to perform unauthorized actions on affected WordPress sites, resulting in low integrity and low availability impacts with no direct confidentiality impact. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity. The scope is limited to the affected WordPress installation, but unauthorized modification of plugin functionality or site data could facilitate further compromise (Patchstack).

Exploitability

No official patch is currently available for this vulnerability, leaving all sites running Get Cash version 3.2.3 or earlier exposed. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the wild, though Patchstack assesses it as expected to be exploited given its unauthenticated nature and suitability for mass-exploit campaigns. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (Patchstack, Feedly).

Mitigation and workarounds

As of the disclosure date, no official patch from the plugin developer (The African Boss) is available. The primary recommended action is to deactivate and remove the Get Cash plugin until an official fix is released. Patchstack has issued a virtual patching/mitigation rule for its subscribers that blocks both legitimate and illegitimate requests to the vulnerable functionality as a temporary protective measure. Site administrators unable to remove the plugin should consult their hosting provider or web developer for assistance (Patchstack).

Community reactions

Patchstack, which coordinated the disclosure after the vulnerability was reported by researcher "Rooting" on September 30, 2025, has flagged this as a medium-priority issue expected to be leveraged in mass-exploit campaigns. No significant vendor statements, broader media coverage, or notable community commentary beyond the Patchstack advisory have been identified (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management