CVE Database /
CVE-2025-47471
CVE · Medium
CVE-2025-47471 — Envo Extra [envo-extra] < 1.9.10
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-47471
|
Envo Extra [envo-extra] < 1.9.10 |
Missing Authorization |
Medium
4.3
|
< 1.9.10
|
1.9.10 |
2025-05-07 |
—
|
CVE-2025-47471
Authenticated users with at least subscriber-level permissions can modify a specific setting due to an oversight in capability checks within the save_domain_switcher_ajax function of Envo Extra plugin versions prior to 1.9.10. This vulnerability allows attackers to alter the chosen domain without proper authorization. The issue affects plugin versions up to, and including, 1.9.9.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings