Description

The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass all role checks and gain full admin privileges.

INFO

Published Date :

2025-07-18T04:23:00.831Z

Last Modified :

2025-07-18T13:47:18.545Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-6813 vulnerability.

No data.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact