Junglewise Threat Intelligence

CVE-2025-66150: Merkulove Appender missing authorization in access control

CVE-2025-66150 · Severity: medium · CVSS 5.4 · Published 2025-12-31

Vendors: Merkulove.

Executive brief

Appender is a WordPress plugin used to manage and display content on websites. A missing authorization vulnerability allows users with Subscriber-level access to perform actions and view data they should not be permitted to access, potentially exposing private or restricted content to unauthorized parties.

Technical details

The Appender WordPress plugin version 1.1.1 and earlier contains a broken access control vulnerability (CWE-284) where authorization checks are either missing or incorrectly configured. An attacker with Subscriber-level privileges can exploit this to access pages, perform administrative actions, or view data that should be restricted to higher privilege levels. The vulnerability is network-accessible via the WordPress front-end and requires only a standard user account to exploit. No official patch is currently available as of the disclosure date.

Affected products

  • Merkulove Appender <= 1.1.1

Timeline

  • 2025-11-10: disclosed: Reported by Phat RiO
  • 2025-12-31: advisory: Published by Patchstack

References