Junglewise Threat Intelligence

CVE-2025-62115: ThemeBoy Hide Plugins broken access control in plugin settings

CVE-2025-62115 · Severity: medium · CVSS 4.3 · Published 2025-12-31

Executive brief

The Hide Plugins WordPress plugin allows administrators to selectively hide certain plugins from other users on their WordPress site. Due to a broken access control vulnerability, users with the Subscriber role (the lowest privilege level) can access plugin management pages and perform actions they should not be permitted to do, such as viewing or managing plugins they shouldn't have access to. This could allow a low-privilege attacker to gain unauthorized visibility or control over site functionality.

Technical details

This vulnerability is a broken access control issue affecting Hide Plugins version 1.0.4 and earlier. The plugin fails to properly validate user permissions before allowing access to plugin management functionalities, allowing users with Subscriber privileges to bypass authorization checks. The attack requires no authentication bypass—an attacker simply needs a valid low-level Subscriber account on the WordPress site. An exploit allows unauthorized users to access or manipulate plugin settings that should be restricted to administrators. No official patch has been released at the time of disclosure; affected sites should update the plugin when a patched version becomes available or implement access restrictions at the hosting level.

Affected products

  • ThemeBoy Hide Plugins <= 1.0.4

Timeline

  • 2025-10-11: disclosed: Reported to Patchstack by Nabil Irawan
  • 2025-12-31: advisory: Vulnerability published by Patchstack and disclosed via CVE-2025-62115

References