Vulnerability Description
The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and overwrite the site’s OpenAI API key and inspection data or modify AI-chat prompts and behavior. This vulnerability is potentially a duplicate of CVE-2025-32208 or/and CVE-2025-32242.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/hive-support/tags/1.2.4/backend/class
- https://plugins.trac.wordpress.org/changeset/3311984
- https://wordpress.org/plugins/hive-support/#developers
- https://www.wordfence.com/threat-intel/vulnerabilities/id/95c8722e-07c3-4728-872
FAQ
What is CVE-2025-5018?
CVE-2025-5018 is a vulnerability with a CVSS score of 7.1 (HIGH). The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_...
How severe is CVE-2025-5018?
CVE-2025-5018 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-5018?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.