Junglewise Threat Intelligence

CVE-2025-62874: Alexander AnyComment broken access control vulnerability

CVE-2025-62874 · Severity: medium · CVSS 4.3 · Published 2025-12-31

Executive brief

AnyComment is a WordPress plugin that enables user comments and discussion features on websites. A broken access control flaw allows subscribers to access pages and perform actions they should not be authorized for, such as viewing other users' data or modifying restricted content. This could lead to unauthorized data exposure or unauthorized actions within the affected WordPress site.

Technical details

The vulnerability is a broken access control issue (OWASP A01:2021) in AnyComment plugin versions up to 0.3.6. The plugin fails to properly enforce authorization checks, allowing authenticated subscribers to access or manipulate content and functionality that should be restricted to higher-privileged roles. The attack requires authentication (subscriber-level account) and is initiated over the network via normal WordPress interaction. An attacker with a subscriber account can bypass intended access restrictions to view sensitive data or perform unauthorized administrative actions. No official patch is currently available for this vulnerability.

Affected products

  • Alexander AnyComment <= 0.3.6

Timeline

  • 2025-09-23: disclosed: Reported by Rooting
  • 2025-12-31: advisory: Published by Patchstack

References