CVE-2025-12093
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-05

Last updated on: 2026-04-08

Assigner: Wordfence

Description
The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to perform several actions like registering an account, deleting users, and modifying details within the employee portal.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-05
Last Modified
2026-04-08
Generated
2026-05-07
AI Q&A
2025-12-10
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
voidek voidek_employee_portal 1.0.6
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
What immediate steps should I take to mitigate this vulnerability?

Immediate steps to mitigate this vulnerability include updating the Voidek Employee Portal plugin to a version later than 1.0.6, such as 1.0.8 or higher, if available. Since the plugin has been temporarily closed and removed from download availability pending a full review, it is recommended to disable or uninstall the plugin until a secure version is released. Additionally, monitor for any updates from the plugin developers or WordPress security advisories. [2]


Can you explain this vulnerability to me?

The Voidek Employee Portal plugin for WordPress has a vulnerability due to missing capability checks on several AJAX actions in versions up to 1.0.6. This allows unauthenticated attackers to perform actions such as registering accounts, deleting users, and modifying details within the employee portal without proper authorization.


How can this vulnerability impact me? :

This vulnerability can allow unauthorized users to manipulate the employee portal by creating accounts, deleting users, or changing user details. This could lead to unauthorized access, data manipulation, and potential disruption of employee management functions.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart