
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54751 is a Missing Authorization (Broken Access Control) vulnerability in the WPXPO PostX WordPress plugin (slug: ultimate-post). It allows authenticated attackers with low privileges (Subscriber-level) to exploit incorrectly configured access control security levels, potentially performing actions beyond their intended permissions. The vulnerability affects PostX versions up to and including 4.1.36, with version 4.1.37 containing the fix. It carries a CVSS v3.1 base score of 7.1 (High), and was published on December 18, 2025, with the underlying security research credited to Abu Hurayra and reported on August 3, 2025 (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning one or more plugin functions fail to properly verify whether the requesting user has the necessary permissions before executing privileged operations (Patchstack). The attack vector is network-based with low attack complexity, requiring only a low-privileged authenticated account (e.g., a Subscriber role) and no user interaction. The missing authorization or nonce check allows an unprivileged user to trigger higher-privileged actions within the plugin, consistent with OWASP Top 10 category A1: Broken Access Control.
Successful exploitation results in a high integrity impact and low confidentiality impact, with no availability impact, according to the CVSS scoring (Patchstack). An attacker with a Subscriber-level account on an affected WordPress site could perform unauthorized privileged actions within the PostX plugin, potentially modifying content, settings, or data they should not have access to. This could lead to content tampering, unauthorized configuration changes, or partial data exposure on affected WordPress installations.
The EPSS score for CVE-2025-54751 is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the wild (Feedly). No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this type (Broken Access Control with a CVSS of 7.1) are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity, making timely patching important (Patchstack).
ultimate-post) at version 4.1.36 or earlier, using tools like WPScan or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/ultimate-post/readme.txt.wp-admin/admin-ajax.php or a REST API route) invoking the privileged action without the expected authorization check.wp-admin/admin-ajax.php or PostX REST API endpoints from low-privileged user accounts, particularly with actions not typical for Subscriber roles.ultimate-post plugin.The vendor WPXPO has released PostX version 4.1.37, which patches this vulnerability; all users should update immediately (Patchstack). Patchstack users benefit from a virtual patching/mitigation rule that blocks exploit attempts until the plugin is updated. If an immediate update is not possible, site administrators should consider disabling the PostX plugin temporarily, restricting user registration to prevent untrusted Subscriber accounts, or contacting their hosting provider for assistance.
Patchstack, which coordinated the disclosure, classifies this as a medium-priority vulnerability and notes that broken access control issues of this type are frequently leveraged in mass WordPress exploit campaigns (Patchstack). The vulnerability was responsibly disclosed by security researcher Abu Hurayra, who reported it on August 3, 2025, with public disclosure following on September 2, 2025. No significant broader media coverage or notable social media discussion has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."