
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64282 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the RadiusTheme Radius Blocks WordPress plugin. It affects all versions through 2.2.1 and was reported on January 13, 2025 by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity), with public disclosure by Patchstack on March 31, 2025. The vulnerability has a CVSS v3.1 base score of 4.3 (Medium), requiring low privileges and no user interaction (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), corresponding to OWASP Top 10 category A1: Broken Access Control. The plugin fails to properly validate that a requesting user is authorized to access specific objects, allowing an attacker to manipulate user-controlled keys (e.g., object IDs in requests) to reference resources they should not have access to. Exploitation requires only a low-privilege authenticated account (Subscriber level) and network access, with no special conditions or user interaction needed (Patchstack).
Successful exploitation allows an authenticated attacker with subscriber-level access to bypass authorization controls and read sensitive application data they are not permitted to access, resulting in a limited confidentiality impact. There is no integrity or availability impact associated with this vulnerability. The scope is limited to the affected WordPress installation, and while the individual impact is low, Patchstack notes that IDOR-class vulnerabilities are commonly leveraged in mass-exploit campaigns targeting large numbers of WordPress sites simultaneously (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. Patchstack classifies the priority as Low, noting the issue is unlikely to be exploited. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack, Red Hat CVE).
/wp-admin/admin-ajax.php or REST API routes associated with the radius-blocks plugin from a single low-privilege user account.As of the time of disclosure, no official patch from RadiusTheme was available for versions through 2.2.1. Site administrators should monitor the RadiusTheme plugin repository for an updated version that addresses this vulnerability and upgrade as soon as one is released. In the interim, consider using a WordPress security plugin such as Patchstack (which offers virtual patching), restricting Subscriber-level user registration if not required, or temporarily deactivating the Radius Blocks plugin if the functionality is non-essential (Patchstack).
The vulnerability received limited public attention, consistent with its low severity rating. Patchstack, the assigning CNA, classified it as low priority with no impactful threat, and the disclosure was routine. No notable researcher commentary, vendor statements beyond the Patchstack advisory, or significant media coverage has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."