Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-25460
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-25460 is a Missing Authorization vulnerability in the LiquidThemes Ave Core WordPress plugin (ave-core) that allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. It affects Ave Core versions from n/a through 2.9.1 (inclusive). The vulnerability was published on March 25, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 6.3 (Medium) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing sensitive actions. An authenticated attacker with low-level privileges (e.g., a subscriber or contributor role) can send crafted network requests to trigger functionality that should be restricted to higher-privileged users. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once an attacker has any valid account on the target WordPress site (Feedly, Patchstack).

Impact

Successful exploitation results in low-level impacts across confidentiality, integrity, and availability — an attacker may be able to read restricted data, modify content or settings, or partially disrupt plugin functionality. Because the scope is unchanged, the impact is contained to the vulnerable WordPress installation rather than enabling direct lateral movement to other systems. However, unauthorized modification of site content or settings could facilitate further attacks such as persistent backdoor installation or privilege escalation within the WordPress environment (Feedly).

Exploitability

The vulnerability requires a low-privileged authenticated account on the target WordPress site, which limits opportunistic mass exploitation but remains a realistic threat in environments with open user registration. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of widespread exploitation. No public proof-of-concept code, active in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the available data (Feedly).

Mitigation and workarounds

Users should update the Ave Core plugin to a version beyond 2.9.1 once a patched release is made available by LiquidThemes. In the interim, site administrators should disable the plugin if it is not essential, restrict user registration to trusted individuals, and audit existing low-privileged accounts for suspicious activity. Implementing a Web Application Firewall (WAF) with WordPress-specific rules (such as those offered by Patchstack or Wordfence) can help block exploitation attempts against unpatched installations (Patchstack).

Community reactions

The vulnerability was reported and assigned by Patchstack, a WordPress security platform, and received minimal broader media or community attention given its medium severity rating. A brief mention appeared on CVEnew social feeds shortly after publication (Feedly).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85009MEDIUM6.5
  • restropress
NoNoSep 16, 2026
CVE-2026-85010MEDIUM5.3
  • restropress
NoYesSep 16, 2026
CVE-2026-86475MEDIUM5.3
  • appointment-hour-booking
NoYesSep 16, 2026
CVE-2026-84906MEDIUM5.3
  • wp-event-solution
NoYesSep 16, 2026
CVE-2026-16557MEDIUM4.3
  • nimble-builder
NoNoSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management