
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64639 is a Missing Authorization (Broken Access Control) vulnerability in the WP Compress for MainWP WordPress plugin. It allows unauthenticated remote attackers to exploit incorrectly configured access control security levels, potentially performing unauthorized actions. The vulnerability affects all versions of WP Compress for MainWP through 6.50.17. It was reported by researcher Legion Hunter on October 30, 2025, and published by Patchstack on November 29, 2025, with CVE assignment on December 16, 2025. The CVSS v3.1 base score is 5.3 (Medium) (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing certain privileged functions. This maps to OWASP Top 10 A1: Broken Access Control. An unauthenticated attacker can send crafted network requests to trigger functionality that should be restricted to authorized users, without needing any credentials or user interaction. No specific technical write-up or proof-of-concept code has been publicly disclosed at this time (Patchstack).
Successful exploitation results in a low integrity impact with no confidentiality or availability impact, meaning an unauthenticated attacker may be able to perform unauthorized write-type actions on affected WordPress sites running the vulnerable plugin. The scope is limited to the affected plugin's functionality within the WordPress/MainWP environment. Patchstack characterizes this as a low-priority issue with no impactful threat, and mass-exploit campaigns targeting WordPress plugins at scale remain a concern even for lower-severity issues (Patchstack).
No public proof-of-concept exploit code has been identified for CVE-2025-64639. The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it theoretically accessible to unauthenticated attackers over the network. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack rates the exploitation likelihood as low (Patchstack).
As of the time of disclosure, no official patch has been released by the plugin developer for WP Compress for MainWP. Patchstack recommends updating the affected plugin as the immediate action; if an update is unavailable, site administrators should consult their hosting provider or web developer. Users of the Patchstack security platform may benefit from virtual patching to mitigate the risk until an official fix is available. Administrators should also consider disabling or removing the plugin if it is not actively needed (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."