CVE-2026-25471 HIGH

CVE-2026-25471: WordPress Admin Safety Guard plugin <= 1.2.6 - Broken Authentication vulnerability

Vendor Themepaste
Product Admin Safety Guard
Weakness CWE-288
Published March 19, 2026
Last update April 28, 2026

CVSS base score

8.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-guard allows Password Recovery Exploitation.This issue affects Admin Safety Guard: from n/a through <= 1.2.6.

Explanation of Vulnerability in Simple Terms

02Summary

Admin Safety Guard versions 1.2.6 and earlier contain an authentication bypass vulnerability. An attacker can exploit this flaw to gain unauthorized access to administrative functions without valid credentials. The vulnerability allows reading sensitive data, modifying site content, and disrupting service availability. Immediate patching is required.

What an attacker can do

03Attacker Capabilities

Bypass authentication to access admin functions, read sensitive data, modify content, and disrupt the site.

Potential impact on your site

04Site Impact

Attackers can take full control of admin functions without a valid password, compromising site security and data.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

March 19, 2026 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE