CVE-2025-6003: CYBERLORD92 WordPress Single Sign-On SSO - Multisite All-Inclusive

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3 versions of the plugin. This makes it possible for unauthenticated attackers to extract sensitive data including site content that has been restricted to certain users and/or roles.

Affected products

  • CYBERLORD92 WordPress Single Sign-On SSO - Multisite All-Inclusive: up to and including 50.5.3
  • CYBERLORD92 WordPress Single Sign-On SSO - Multisite Enterprise: up to and including 40.5.3
  • CYBERLORD92 WordPress Single Sign-On SSO - Multisite Premium: up to and including 30.5.3
  • CYBERLORD92 WordPress Single Sign-On SSO - Single Site All-Inclusive: up to and including 48.5.3
  • CYBERLORD92 WordPress Single Sign-On SSO - Single Site Enterprise: up to and including 38.5.3
  • CYBERLORD92 WordPress Single Sign-On SSO - Single Site Premium: up to and including 28.5.3
  • CYBERLORD92 WordPress Single Sign-On SSO - Single Site Standard: up to and including 18.5.3

Published 2025-06-12. Last modified 2026-06-17.