The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to modify several of the plugin's settings like the ServerKey and LicenseKey.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Tue, 11 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to modify several of the plugin's settings like the ServerKey and LicenseKey. | |
| Title | Shelf Planner <= 2.7.0 - Missing Authorization to Unauthenticated Settings Update | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-11T03:30:31.772Z
Updated: 2025-11-12T20:09:24.765Z
Reserved: 2025-10-16T20:35:18.671Z
Link: CVE-2025-11894
Updated: 2025-11-12T17:30:40.902Z
Status : Awaiting Analysis
Published: 2025-11-11T04:15:44.613
Modified: 2025-11-12T16:19:34.210
Link: CVE-2025-11894
No data.