CVE-2026-25012

WordPress WP Bannerize Pro plugin <= 1.11.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in gfazioli WP Bannerize Pro wp-bannerize-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bannerize Pro: from n/a through <= 1.11.0.


We have discovered 358 live websites that are affected by CVE-2026-25012.

Run a Free Instant Scan




Affected Software

Product  Wp Bannerize Pro
Category Wordpress Plugins
Vulnerable Domains358 live websites (93% of Wp Bannerize Pro install base)
Vulnerable Versions
  • from 0 through 1.11
Vulnerable Versions Count20 versions ( 95% of all versions)



Details

  • Published - Feb 3, 2026
  • Updated - Feb 3, 2026

Credits

  • theviper17 | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-25012
United States50 websites



Brazil98 websites
Italy61 websites
Germany17 websites
Russia15 websites
Poland11 websites
Spain10 websites
Cyprus8 websites
France8 websites
Czech Republic6 websites

Website Distribution by TLD

Number of websites using CVE-2026-25012
.com.br94 websites
.com88 websites
.it45 websites
.ru11 websites
.org9 websites
.net9 websites
.de9 websites
.pl8 websites
.at5 websites
.nl4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25012

Top websites that are affected by CVE-2026-25012. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.it Italy***,***
********.com Germany***,***
****.********.ca Canada***,***
***********.it Italy***,***
*********************.de Germany***,***
***.***.mt Malta***,***
******.at Austria***,***
*************.pl Poland***,***
***************.de Germany***,***
**********.ro Romania***,***
See full domain list

FAQ

A total of 358 websites have been identified as vulnerable to CVE-2026-25012, based on global website indexing conducted by WebTechSurvey.
The Wp Bannerize Pro is affected by the CVE-2026-25012 vulnerability.
Wp Bannerize Pro versions up to and including 1.11 are vulnerable to CVE-2026-25012.