CVE-2025-47563

WordPress CURCY plugin <= 2.3.7 - Arbitrary Shortcode Execution vulnerability

Missing Authorization vulnerability in villatheme CURCY allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CURCY: from n/a through 2.3.7.


We have discovered 2,546 live websites that are affected by CVE-2025-47563.

Run a Free Instant Scan




Affected Software

Product  CURCY
Category Wordpress Plugins
Vulnerable Domains2,546 live websites (87.85% of CURCY install base)
Vulnerable Versions
  • from 0 through 2.3.7
Vulnerable Versions Count64 versions ( 96.97% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - May 16, 2025
  • Updated - May 16, 2025

Credits

  • Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance) (finder)

CVE-2025-47563 usage by Country

United States1,170 websites



Turkey196 websites
Germany190 websites
Cyprus151 websites
GB126 websites
France88 websites
Poland70 websites
Canada39 websites
South Africa32 websites
Denmark32 websites

CVE-2025-47563 usage by TLD

.com1,627 websites
.net57 websites
.co.uk53 websites
.de53 websites
.es46 websites
.org46 websites
.it37 websites
.pl31 websites
.eu27 websites
.ca23 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-47563

Top websites that are affected by CVE-2025-47563. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com Denmark**,***
********.com Germany***,***
************.*****.com United States***,***
*****.org Germany***,***
***********.net United States***,***
*****.com United States***,***
***************.com United States***,***
******.com United States***,***
*********.*********.com United States***,***
****************.ca United States***,***
See full domain list

FAQ

CVE-2025-47563 is Missing Authorization in CURCY
A total of 2,546 websites have been identified as vulnerable to CVE-2025-47563, based on global website indexing conducted by WebTechSurvey.
The CURCY is affected by the CVE-2025-47563 vulnerability.
CURCY versions up to and including 2.3.7 are vulnerable to CVE-2025-47563.