CVE-2025-69313 is a Missing Authorization vulnerability in the WPXPO PostX ultimate-post plugin, affecting versions up to and including 5.0.3. This flaw allows for the exploitation of incorrectly configured access control, potentially leading to high confidentiality impact without requiring user interaction or authentication. Rated with a CVSS score of 7.5 (HIGH), it presents a significant risk, though there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB). Despite the lack of active exploitation, the vulnerability has garnered considerable community discussion with 10 mentions, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 5.0.3CPE match | cpe:2.3:a:wpxpo:postx:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.