
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58877 is a Missing Authorization vulnerability in the Javo Core WordPress plugin (by javothemes) that allows unauthenticated attackers to perform arbitrary content deletion. It affects all versions of Javo Core up to and including 3.0.0.529. The vulnerability was reported on July 27, 2025, and published by Patchstack on August 26, 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has the necessary permissions before executing content deletion operations. Because no authentication or capability check is enforced on the vulnerable endpoint, a remote, unauthenticated attacker can send crafted network requests to trigger deletion of arbitrary WordPress content (posts, pages, images, etc.). The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity (Patchstack).
Successful exploitation allows an unauthenticated attacker to delete arbitrary content from an affected WordPress site, including posts, pages, and media files. This results in a high availability impact and potential destruction of site content, though confidentiality and integrity of data (beyond deletion) are not directly affected per the CVSS assessment. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of websites simultaneously, regardless of site size or traffic (Patchstack).
action=javo_delete_content&post_id=<ID>)./wp-admin/admin-ajax.php) or REST API routes associated with Javo Core plugin actions; high-volume requests from a single IP targeting content deletion parameters.wp_posts table with no corresponding admin user activity in audit logs.As of the publication date, no official patch is available from the plugin developer (javothemes). Patchstack has issued a virtual patching/mitigation rule for Patchstack-protected sites to block exploitation attempts until an official fix is released. Site administrators should consider temporarily deactivating the Javo Core plugin if it is not essential, restricting access to WordPress AJAX and REST API endpoints via firewall rules where possible, and monitoring for the plugin developer releasing an updated version above 3.0.0.529 (Patchstack).
Patchstack, which discovered and disclosed the vulnerability (credited to researcher 'Bonds'), classifies it as high priority and warns of mass-exploit campaign potential. No significant vendor statement from javothemes, broader media coverage, or notable social media discussion has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."