CVE-2025-62929
8.8PickPlugins · Testimonial Slider
A missing authorization vulnerability in the PickPlugins Testimonial Slider plugin allows authenticated users to exploit broken access controls.
Executive summary
A missing authorization flaw in the PickPlugins Testimonial Slider plugin allows authenticated users to access restricted information, posing a significant risk to data confidentiality.
Vulnerability
This vulnerability is a missing authorization flaw (CWE-862) that permits an authenticated user to perform actions or access data beyond their intended privilege level due to incorrectly configured access control checks.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high level of severity. Successful exploitation could lead to unauthorized access to sensitive data handled by the plugin, potentially resulting in information disclosure and a breach of organizational data privacy standards.
Remediation
Immediate Action: Review the official PickPlugins vendor advisory for the release of a security patch and update the Testimonial Slider plugin to the latest version immediately upon availability.
Proactive Monitoring: Monitor WordPress access logs for suspicious activity or unauthorized attempts to access plugin-specific endpoints, particularly those originating from low-privileged user accounts.
Compensating Controls: If a patch is not yet available, consider temporarily deactivating the Testimonial Slider plugin or implementing Web Application Firewall (WAF) rules to block unauthorized requests to the vulnerable plugin endpoints.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the high CVSS score of 8.8, this vulnerability represents a significant security risk for any organization utilizing the affected software. Administrators should prioritize monitoring for vendor updates and apply the necessary patches as soon as they are released to prevent potential unauthorized access to sensitive plugin data.
More PickPlugins CVEs
Sources
Originally found and disclosed by Abu Hurayra | Patchstack Bug Bounty Program, per the CVE Program record.