CVE-2025-28995: WordPress Viral Loops WP Integration <= 3.8.1 - Broken Access Control Vulnerability

5.3 CVSS

Description

Missing Authorization vulnerability in viralloops Viral Loops WP Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Viral Loops WP Integration: from n/a through 3.8.1.

Classification

CVE ID: CVE-2025-28995

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem Types

CWE-862 Missing Authorization

Affected Products

Vendor: viralloops

Product: Viral Loops WP Integration

References

https://nvd.nist.gov/vuln/detail/CVE-2025-28995
https://patchstack.com/database/wordpress/plugin/viral-loops-wp-integration/vulnerability/wordpress-viral-loops-wp-integration-3-8-1-broken-access-control-vulnerability?_s_id=cve

Timeline