CVE · Medium

CVE-2025-50010 — Zapier for WordPress [zapier] < 1.5.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-50010 Zapier for WordPress [zapier] < 1.5.3 Missing Authorization Medium 5.4 < 1.5.3 1.5.3 2025-06-19

CVE-2025-50010

A security flaw exists within the Zapier for WordPress plugin, affecting all versions prior to 1.5.3. The issue stems from a lack of capability verification in certain plugin functions, allowing users with Subscriber permissions or higher to execute unauthorized actions. This vulnerability is present across all affected versions, including 1.5.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.