CVE-2025-31643
8.8Dasinfomedia · WPCHURCH
An incorrect privilege assignment vulnerability in the Dasinfomedia WPCHURCH WordPress plugin allows authenticated users to escalate their privileges.
Executive summary
A critical privilege escalation vulnerability in the WPCHURCH plugin allows authenticated users to gain unauthorized administrative access, posing a severe threat to site integrity.
Vulnerability
This vulnerability involves an Incorrect Privilege Assignment (CWE-266) within the plugin, which allows an authenticated user with low-level privileges to escalate their access to higher levels.
Business impact
Successful exploitation of this flaw allows attackers to perform unauthorized actions, potentially leading to full site compromise, data exfiltration, or the injection of malicious content. With a CVSS score of 8.8, this high-severity vulnerability represents a significant risk to organizational data and operational continuity.
Remediation
Immediate Action: Administrators must update the WPCHURCH plugin to the version containing the security fix immediately. If a patch is not yet available, deactivate the plugin until the vendor releases a secure version.
Proactive Monitoring: Review WordPress user account logs for suspicious activity, such as unexpected privilege changes or the creation of new administrator accounts by unauthorized users.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common privilege escalation patterns and unauthorized requests to administrative plugin functions.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the nature of privilege escalation, this vulnerability should be prioritized for immediate remediation. Security teams must ensure that all installations of the WPCHURCH plugin are audited and updated to the latest available version to prevent unauthorized access and potential system takeover.
More Dasinfomedia CVEs
Sources
Originally found and disclosed by Aiden | Patchstack Bug Bounty Program, per the CVE Program record.