CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-4654: Soumettre.fr <= 2.1.5 - Improper Authorization to Unauthenticated Soumettre Posts Creation/Modification/Deletion

3.7 CVSS

Description

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper authorization checks on the make_signature function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create/edit/delete Soumettre posts. This vulnerability affects only installations where the soumettre account is not connected (i.e. API key is not installed)

Classification

CVE ID: CVE-2025-4654

CVSS Base Severity: LOW

CVSS Base Score: 3.7

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem Types

CWE-285 Improper Authorization

Affected Products

Vendor: soumettre

Product: Soumettre.fr

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 13.5% (scored less or equal to compared to others)

EPSS Date: 2025-07-04 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-4654
https://www.wordfence.com/threat-intel/vulnerabilities/id/4f29d476-0730-437c-8065-309523278efa?source=cve
https://plugins.trac.wordpress.org/browser/soumettre-fr/tags/2.1.5/public/rest/class-soumettre-rest-route.php#L211

Timeline