Vulnerability Description
The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the wp_ajax_nopriv_ce21_single_sign_on_save_api_settings AJAX action in versions 2.2.1 to 2.3.1. This makes it possible for unauthenticated attackers to update the plugin's API settings including a secret key used for authentication. This allows unauthenticated attackers to create new admin accounts on an affected site.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/ce21-suite/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5e24feac-1812-45d7-b3c
FAQ
What is CVE-2025-11007?
CVE-2025-11007 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the wp_ajax_nopriv_ce21_single_sign_on_save_api_settings AJAX action in ve...
How severe is CVE-2025-11007?
CVE-2025-11007 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-11007?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.