Junglewise Threat Intelligence

CVE-2025-66149: merkulove UnGrabber broken access control vulnerability

CVE-2025-66149 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

UnGrabber is a WordPress plugin used to manage and optimize image handling on websites. A broken access control flaw allows subscribers and other low-privilege users to access pages and perform actions they should not be permitted to, such as viewing private data or modifying content belonging to other users.

Technical details

This is a broken access control vulnerability in the UnGrabber WordPress plugin (versions <= 3.1.3). The vulnerability allows authenticated users with subscriber-level privileges to bypass authorization checks and perform unauthorized actions on pages or data they should not have access to. The vulnerability is exploitable without elevated privileges and requires only an authenticated account. No official patch is currently available; administrators should update the plugin once a patched version is released or consider disabling the plugin until mitigation is available.

Affected products

  • merkulove UnGrabber <= 3.1.3

Timeline

  • 2025-11-10: disclosed: Reported by Phat RiO
  • 2025-12-31: advisory: Published by Patchstack

References