CVE · Medium

CVE-2025-47471 — Envo Extra [envo-extra] < 1.9.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-47471 Envo Extra [envo-extra] < 1.9.10 Missing Authorization Medium 4.3 < 1.9.10 1.9.10 2025-05-07

CVE-2025-47471

Authenticated users with at least subscriber-level permissions can modify a specific setting due to an oversight in capability checks within the save_domain_switcher_ajax function of Envo Extra plugin versions prior to 1.9.10. This vulnerability allows attackers to alter the chosen domain without proper authorization. The issue affects plugin versions up to, and including, 1.9.9.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.