
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25460 is a Missing Authorization vulnerability in the LiquidThemes Ave Core WordPress plugin (ave-core) that allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. It affects Ave Core versions from n/a through 2.9.1 (inclusive). The vulnerability was published on March 25, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 6.3 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing sensitive actions. An authenticated attacker with low-level privileges (e.g., a subscriber or contributor role) can send crafted network requests to trigger functionality that should be restricted to higher-privileged users. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once an attacker has any valid account on the target WordPress site (Feedly, Patchstack).
Successful exploitation results in low-level impacts across confidentiality, integrity, and availability — an attacker may be able to read restricted data, modify content or settings, or partially disrupt plugin functionality. Because the scope is unchanged, the impact is contained to the vulnerable WordPress installation rather than enabling direct lateral movement to other systems. However, unauthorized modification of site content or settings could facilitate further attacks such as persistent backdoor installation or privilege escalation within the WordPress environment (Feedly).
The vulnerability requires a low-privileged authenticated account on the target WordPress site, which limits opportunistic mass exploitation but remains a realistic threat in environments with open user registration. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of widespread exploitation. No public proof-of-concept code, active in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the available data (Feedly).
Users should update the Ave Core plugin to a version beyond 2.9.1 once a patched release is made available by LiquidThemes. In the interim, site administrators should disable the plugin if it is not essential, restrict user registration to trusted individuals, and audit existing low-privileged accounts for suspicious activity. Implementing a Web Application Firewall (WAF) with WordPress-specific rules (such as those offered by Patchstack or Wordfence) can help block exploitation attempts against unpatched installations (Patchstack).
The vulnerability was reported and assigned by Patchstack, a WordPress security platform, and received minimal broader media or community attention given its medium severity rating. A brief mention appeared on CVEnew social feeds shortly after publication (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."