CVE-2025-30624

WordPress WordLift <= 3.54.4 - Broken Access Control Vulnerability

Missing Authorization vulnerability in WordLift WordLift allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordLift: from n/a through 3.54.4.


We have discovered 382 live websites that are affected by CVE-2025-30624.

Run a Free Instant Scan




Affected Software

Product  WordLift
Category Search Engine Optimization
Vulnerable Domains382 live websites (100% of WordLift install base)
Vulnerable Versions
  • from 0 through 3.54.4
Vulnerable Versions Count28 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jun 6, 2025
  • Updated - Jun 6, 2025

Credits

  • Nguyen Tran Tuan Dung (domiee13) (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-30624
United States214 websites



Germany55 websites
Italy41 websites
France12 websites
Sweden9 websites
Cyprus6 websites
GB5 websites
Netherlands5 websites
Austria4 websites
Bulgaria4 websites

Website Distribution by TLD

Number of websites using CVE-2025-30624
.com222 websites
.it50 websites
.org12 websites
.at9 websites
.nl8 websites
.net8 websites
.fr8 websites
.ca6 websites
.co.uk5 websites
.io4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-30624

Top websites that are affected by CVE-2025-30624. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.com United States*,***
***********.com United States**,***
**********.com United States**,***
**************.com Germany**,***
**********.com France**,***
******************.com France**,***
********.com United States**,***
********.io United States***,***
******************.com United States***,***
*****************.com United States***,***
See full domain list

FAQ

CVE-2025-30624 is Missing Authorization in WordLift
A total of 382 websites have been identified as vulnerable to CVE-2025-30624, based on global website indexing conducted by WebTechSurvey.
The WordLift is affected by the CVE-2025-30624 vulnerability.
WordLift versions up to and including 3.54.4 are vulnerable to CVE-2025-30624.