
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64245 is a Missing Authorization (Broken Access Control) vulnerability in the WordPress plugin "Import external attachments" by ryanpcmcquen. It allows authenticated attackers with low privileges (Subscriber level) to exploit incorrectly configured access control security levels, potentially performing actions beyond their intended permissions. All versions up to and including 1.5.12 are affected, and no official patch was available at the time of disclosure. The vulnerability was reported by Nabil Irawan on November 14, 2025, and published by Patchstack on December 14–16, 2025, with a CVSS v3.1 base score of 4.3 (Medium) (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning one or more plugin functions fail to perform adequate authorization checks before executing privileged actions. An authenticated user with Subscriber-level access can send crafted network requests to trigger functionality that should be restricted to higher-privileged roles (e.g., administrators or editors). The attack requires no user interaction, has low complexity, and is exploitable over the network, but does not result in confidentiality or availability impact — only a low integrity impact (Patchstack, Feedly).
Successful exploitation allows a low-privileged authenticated user (Subscriber) to perform unauthorized actions within the WordPress plugin's functionality, resulting in a limited integrity impact. There is no confidentiality or availability impact based on the CVSS assessment. The scope is limited to the affected WordPress installation, and lateral movement or significant data exposure is not a primary concern for this vulnerability (Patchstack).
As of the time of disclosure, no official patched version of the "Import external attachments" plugin was available. Site administrators should monitor the plugin's repository for an updated release and apply it as soon as one becomes available. In the interim, consider deactivating and removing the plugin if it is not critical to site operations, or restricting Subscriber-level user registration to reduce the attack surface. Patchstack users may benefit from virtual patching protections offered by the platform (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."