CVE-2025-62888
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62888 is a Missing Authorization (Broken Access Control) vulnerability in the WP Attachments WordPress plugin by Marco Milesi, affecting all versions up to and including 5.2. The flaw allows authenticated attackers with low privileges (Contributor or Developer role) to exploit incorrectly configured access control security levels and perform actions beyond their intended permissions. It was reported by researcher Jitlada on October 9, 2025, and publicly disclosed by Patchstack on December 31, 2025. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Patchstack, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks — such as capability checks or nonce token validation — before executing privileged functions. This allows a low-privileged authenticated user (e.g., a Contributor) to invoke actions that should be restricted to higher-privileged roles. The attack vector is network-based, requires low privileges, no user interaction, and low attack complexity. No public proof-of-concept exploit code has been identified at this time (Patchstack).

Impact

Successful exploitation can result in limited integrity and availability impacts on the affected WordPress site, as an attacker with a low-privileged account could perform unauthorized actions such as modifying or deleting attachments managed by the plugin. Confidentiality is not directly impacted according to the CVSS assessment. While the individual impact is moderate, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Attachments plugin version 5.2 or earlier using tools like WPScan or Shodan, or by checking the plugin version in the site's /wp-content/plugins/wp-attachments/ directory.
  2. Obtain low-privileged access: Register or obtain credentials for a Contributor or Developer account on the target WordPress site.
  3. Identify unprotected endpoints: Enumerate AJAX actions or admin endpoints exposed by the WP Attachments plugin that lack proper capability or nonce checks.
  4. Send unauthorized request: Craft and submit an HTTP request (e.g., a POST to wp-admin/admin-ajax.php with the relevant action parameter) to invoke a privileged function — such as modifying or deleting attachments — without the required authorization.
  5. Achieve unauthorized action: The server processes the request without validating the user's privilege level, allowing the attacker to perform actions reserved for higher-privileged roles (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to wp-admin/admin-ajax.php with WP Attachments-related action parameters from low-privileged user accounts; repeated requests from the same authenticated session targeting attachment management functions.
  • Application: Unexplained modification or deletion of media attachments in the WordPress media library not attributable to administrator actions.
  • User Activity: Contributor or Developer accounts performing attachment management operations outside their normal scope, visible in WordPress activity logs if an audit plugin is installed.

Mitigation and workarounds

The vendor has released version 5.2.1 of the WP Attachments plugin, which patches this vulnerability. Site administrators should update to version 5.2.1 or later immediately via the WordPress plugin dashboard. If an immediate update is not possible, consider restricting Contributor-level registrations or using a WordPress security plugin such as Patchstack, which can provide virtual patching to block exploitation attempts until the plugin is updated (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13147CRITICAL9.1
  • kirki
NoYesJul 20, 2026
CVE-2026-9833HIGH7.1
  • tag-groups
NoYesJul 20, 2026
CVE-2026-13432MEDIUM5.4
  • image-sizes
NoYesJul 20, 2026
CVE-2026-13156MEDIUM5.4
  • mailersend-official-smtp-integration
NoYesJul 20, 2026
CVE-2026-8825MEDIUM4.9
  • elementor
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management