CVE-2025-64294 identifies a Missing Authorization vulnerability (CWE-862) in the d3wp WP Snow Effect plugin, affecting versions up to and including 1.1.19. This flaw allows an unauthenticated attacker to access functionality not properly constrained by access control lists. Rated Medium with a CVSS score of 5.3, it has a low attack complexity and can be exploited over the network, potentially leading to unauthorized modification of data or settings. There is currently no evidence of active exploitation, nor are public exploit codes available in common repositories. Community discussion and media coverage are minimal, indicating very low attention and a low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| D3wp | WP Snow Effect | >= 0, <= 1.1.19CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.