Agency Toolkit <= 1.0.23 - Unauthenticated Privilege Escalation
critical
The Agency Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.23. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 1.0.23
- Fixed in:
- 1.0.24
- Disclosed:
- Dec 18, 2025
CVE-2024-56066 on NVD →
Agency Toolkit <= 1.0.24 - Missing Authorization
medium
The Agency Toolkit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.0.24. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.0.24
- Fixed in:
- 1.0.25
- Disclosed:
- Apr 1, 2025
CVE-2025-31863 on NVD →
Agency Toolkit <= 1.0.23 - Missing Authorization to Unauthenticated Arbitrary Options Update
critical
The Agency Toolkit plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'agency_toolkit_import' action in all versions up to, and including, 1.0.23. This makes it possible for unauthenticated attackers to update arbitrary...
- CVSS:
- 9.8
- Affected:
- up to 1.0.23
- Fixed in:
- 1.0.24
- Disclosed:
- Dec 17, 2024
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database