CVE-2025-12004 Details
Description
Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Extension allows Privilege Abuse. Fixed in Mediawiki Core Action APIThis issue affects Mediawiki - Lockdown Extension: from master before 1.42.
A vulnerability in the MediaWiki Lockdown Extension allows users with read permission to access content that should be protected. This issue arises because the Action API module 'compare' fails to properly check permissions, enabling unauthorized access to restricted content. The vulnerability affects MediaWiki Lockdown Extension versions prior to 1.42.
This vulnerability has been fixed in MediaWiki core versions 1.42, 1.43, and 1.44. Users should update to one of these versions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 21, 2025CISA-ADP
Assessed Oct 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://phabricator.wikimedia.org/T397521 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://gerrit.wikimedia.org/r/q/Id275382743957004fa7fc56318fc104d8e2d267b | wikimedia-foundation | Source CodeVendor |
| https://phabricator.wikimedia.org/T397521 | wikimedia-foundation | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | wikimedia-foundation |
Affected Products
| Product | Versions |
|---|---|
| Wikimedia Foundation Mediawiki - Lockdown Extension | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | wikimedia-foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | New CVE Received | wikimedia-foundation |
Volerion