
CVE-2025-54049 Critical Privilege Escalation in Miniorange Custom API for WP. CVSS 9.9. Unpatched in versions <= 4.2.2. Disable plugin immediately. #CVE #WordPress #infosec #CVEAlert #DevOps #Develoeprs Patch, Test Lab and other CVES available: https://www.valtersit.com/cve/CVE-2025-54049/
Post summary
CVE‑2025‑54049 is a critical privilege‑escalation bug in Miniorange Custom API for WordPress (CVSS 9.9) with vulnerable versions <=4.2.2; users are advised to disable or patch the plugin, with further mitigation details linked.
