CVE-2025-64245
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64245 is a Missing Authorization (Broken Access Control) vulnerability in the WordPress plugin "Import external attachments" by ryanpcmcquen. It allows authenticated attackers with low privileges (Subscriber level) to exploit incorrectly configured access control security levels, potentially performing actions beyond their intended permissions. All versions up to and including 1.5.12 are affected, and no official patch was available at the time of disclosure. The vulnerability was reported by Nabil Irawan on November 14, 2025, and published by Patchstack on December 14–16, 2025, with a CVSS v3.1 base score of 4.3 (Medium) (Patchstack).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), meaning one or more plugin functions fail to perform adequate authorization checks before executing privileged actions. An authenticated user with Subscriber-level access can send crafted network requests to trigger functionality that should be restricted to higher-privileged roles (e.g., administrators or editors). The attack requires no user interaction, has low complexity, and is exploitable over the network, but does not result in confidentiality or availability impact — only a low integrity impact (Patchstack, Feedly).

Impact

Successful exploitation allows a low-privileged authenticated user (Subscriber) to perform unauthorized actions within the WordPress plugin's functionality, resulting in a limited integrity impact. There is no confidentiality or availability impact based on the CVSS assessment. The scope is limited to the affected WordPress installation, and lateral movement or significant data exposure is not a primary concern for this vulnerability (Patchstack).

Mitigation and workarounds

As of the time of disclosure, no official patched version of the "Import external attachments" plugin was available. Site administrators should monitor the plugin's repository for an updated release and apply it as soon as one becomes available. In the interim, consider deactivating and removing the plugin if it is not critical to site operations, or restricting Subscriber-level user registration to reduce the attack surface. Patchstack users may benefit from virtual patching protections offered by the platform (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13147CRITICAL9.1
  • kirki
NoYesJul 20, 2026
CVE-2026-9833HIGH7.1
  • tag-groups
NoYesJul 20, 2026
CVE-2026-13432MEDIUM5.4
  • image-sizes
NoYesJul 20, 2026
CVE-2026-13156MEDIUM5.4
  • mailersend-official-smtp-integration
NoYesJul 20, 2026
CVE-2026-8825MEDIUM4.9
  • elementor
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management