Sweet Energy Efficiency <= 1.0.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Graph Deletion
2025-12-17 23:38
Paolo TressoStrategic Overview
StatusPatched in 1.0.7
Affected PluginSweet Energy Efficiency
Affected Version
<= 1.0.6CVSS4.3Medium
CVE
CVE-2025-14618Vulnerability Overview
The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on the 'sweet_energy_efficiency_action' AJAX handler in all versions up to, and including, 1.0.6. This makes it possible for authenticated attackers, with subscriber level access and above, to read, modify, and delete arbitrary graphs.
Technical Analysis
REMEDIATION: Update to version 1.0.7, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C