Voidek Employee Portal Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the Voidek Employee Portal plugin for WordPress, all versions through 1.0.6, due to a lack of proper capability checks on several AJAX actions. This flaw allows unauthenticated users to gain unauthorized access and perform actions such as registering accounts, deleting users, and altering details within the employee portal.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed within the employee portal, including user account creation, user deletion, and modification of portal details.

Remediation

No known patch is available. It is recommended to review the vulnerability details thoroughly and consider uninstalling the affected plugin.

Added: Dec 5, 2025, 7:21 AM
Updated: Dec 5, 2025, 7:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
7.4
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.