CVE-2025-54741
8.6Tyler Moore · Super Blank
A missing authorization vulnerability in the Tyler Moore Super Blank plugin allows authenticated users to trigger arbitrary content deletion through improper access control.
Executive summary
A missing authorization vulnerability in the Tyler Moore Super Blank plugin allows authenticated attackers to perform unauthorized actions, potentially leading to significant service disruption.
Vulnerability
The vulnerability is a missing authorization flaw (CWE-862) that permits an authenticated user with low privileges to bypass access control checks. This enables the attacker to interact with restricted functions, specifically leading to arbitrary content deletion.
Business impact
The ability for an unauthorized user to delete content poses a severe risk to data integrity and operational continuity. With a CVSS score of 8.6, this vulnerability is classified as High, as it can lead to permanent data loss and significant administrative overhead to restore affected systems.
Remediation
Immediate Action: Since no specific patch version is currently identified, administrators should immediately deactivate and remove the Super Blank plugin from their WordPress environments until a secure update is provided by the vendor.
Proactive Monitoring: Review web server and WordPress audit logs for unusual deletion requests originating from low-privileged user accounts.
Compensating Controls: Implement a Web Application Firewall (WAF) to block suspicious requests targeting plugin-specific endpoints, though this should be considered a temporary measure pending plugin removal.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the nature of the flaw, organizations utilizing the Super Blank plugin must treat this as a priority. Administrators are strongly advised to deactivate the plugin immediately to prevent potential exploitation until a verified security update is released by the developer.
More Tyler Moore CVEs
Sources
Originally found and disclosed by Denver Jackson | Patchstack Bug Bounty Program, per the CVE Program record.