Executive brief
WP Custom Admin Interface is a WordPress plugin that manages administrative interface configurations and access levels. A broken access control vulnerability in versions up to 7.40 allows subscribers with minimal privileges to access administrative pages or perform actions they should not be permitted to perform, potentially exposing sensitive configuration or administrative functions.
Technical details
This is a broken access control vulnerability (CWE-639) affecting WP Custom Admin Interface plugin through version 7.40. The vulnerability stems from incorrectly configured access control checks that fail to properly validate user permissions before exposing administrative interface pages or actions. An authenticated attacker with subscriber-level privileges can exploit this by directly accessing or invoking administrative functions without proper authorization. The vulnerability requires authentication (user must have at least subscriber access) but does not require elevated privileges. A patch is available in version 7.41 and later.
Affected products
- Northern Beaches Websites WP Custom Admin Interface through 7.40
Timeline
- 2025-10-05: disclosed: Reported by Jitlada
- 2025-12-31: advisory: Published by Patchstack
- 2025-12-31: patched: Fix available in version 7.41