CVE-2025-12165
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-05

Last updated on: 2026-04-08

Assigner: Wordfence

Description
The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webcake_save_config' AJAX endpoint in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-05
Last Modified
2026-04-08
Generated
2026-05-07
AI Q&A
2025-12-05
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
huyme webcake 1.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Webcake – Landing Page Builder plugin for WordPress, where a missing capability check on the 'webcake_save_config' AJAX endpoint allows authenticated users with Subscriber-level access or higher to modify the plugin's settings without proper authorization.


How can this vulnerability impact me? :

An attacker with at least Subscriber-level access can modify the plugin's settings, potentially leading to unauthorized changes in the website's landing page configurations, which could affect site behavior or security.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update the Webcake – Landing Page Builder plugin to version 1.2 or later, as the vulnerability affects all versions up to and including 1.1. Additionally, restrict Subscriber-level access if possible and monitor plugin settings for unauthorized changes. [2]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart