CVE-2025-49974 Information

Description

Missing Authorization vulnerability in upstreamplugin UpStream: a Project Management Plugin for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects UpStream: a Project Management Plugin for WordPress: from n/a through 2.1.0.

Reference

https://patchstack.com/database/wordpress/plugin/upstream/vulnerability/wordpress-upstream-a-project-management-plugin-for-wordpress-plugin-2-1-0-broken-access-control-vulnerability?_s_id=cve

CNNVD-202506-2694 (Published: 2025-06-20)

Share on: