CVE-2025-58976
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-09

Last updated on: 2026-04-23

Assigner: Patchstack

Description
Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.31.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-09
Last Modified
2026-04-23
Generated
2026-05-07
AI Q&A
2025-09-09
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
equalize_digital accessibility_checker *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a Missing Authorization issue in the Equalize Digital Accessibility Checker plugin for WordPress, affecting versions up to 1.31.0. It occurs because certain functions lack proper authorization, authentication, or nonce token checks, allowing users with low-level privileges (subscriber-level) to perform actions that should be restricted to higher-privileged roles. This is classified as a broken access control vulnerability. [1]


How can this vulnerability impact me? :

The vulnerability allows users with subscriber-level privileges to perform unauthorized actions reserved for higher-privileged roles, potentially leading to unauthorized access or changes within the plugin's functionality. Although the risk is considered low priority and exploitation is unlikely, it could still compromise the integrity of access controls in the system. [1]


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should update the WordPress Accessibility Checker plugin by Equalize Digital to version 1.31.1 or later, as these versions include a fix for the broken access control issue. As an interim measure, you can use Patchstack's virtual patching (vPatching) service, which automatically mitigates the vulnerability even before official patches are applied. Avoid allowing subscriber-level users to perform actions reserved for higher-privileged roles until the update or virtual patch is applied. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart