CVE-2025-6003

MEDIUM

WordPress SSO <*.5.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3 versions of the plugin. This makes it possible for unauthenticated attackers to extract sensitive data including site content that has been restricted to certain users and/or roles.

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (7)
cyberlord92/WordPress Single Sign-On (SSO) - Multisite All-Inclusive < 50.5.3
cyberlord92/WordPress Single Sign-On (SSO) - Multisite Enterprise < 40.5.3
cyberlord92/WordPress Single Sign-On (SSO) - Multisite Premium < 30.5.3
cyberlord92/WordPress Single Sign-On (SSO) - Single Site All-Inclusive < 48.5.3
cyberlord92/WordPress Single Sign-On (SSO) - Single Site Enterprise < 38.5.3
cyberlord92/WordPress Single Sign-On (SSO) - Single Site Premium < 28.5.3
cyberlord92/WordPress Single Sign-On (SSO) - Single Site Standard < 18.5.3
Published Jun 12, 2025
Tracked Since Feb 18, 2026