What is CVE-2026-25424?
This vulnerability involves a Broken Access Control issue for Contributor-level users in Mediavine Control Panel versions 2.10.10 and below. It allows lower-privileged users to access administrative functions they should not have permission to. Updating the plugin to the latest version is recommended.
Azərbaycanca: Bu zəiflik Mediavine Control Panel plagininin 2.10.10 və daha əvvəl versiyalarında Contributor rolunda olan istifadəçilər üçün Broken Access Control problemini əhatə edir. Bu, aşağı səlahiyyətli istifadəçilərə normalda icazəsi olmayan idarəetmə funksiyalarına giriş imkanı yaradır. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which plugin does CVE-2026-25424 affect?
This vulnerability affects the Mediavine Control Panel plugin.
What is the minimum user role affected by this Broken Access Control issue?
The vulnerability affects users with the Contributor role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.