CVE-2025-5018 Details
Description
The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and overwrite the site’s OpenAI API key and inspection data or modify AI-chat prompts and behavior. This vulnerability is potentially a duplicate of CVE-2025-32208 or/and CVE-2025-32242.
A vulnerability exists in the Hive Support plugin for WordPress, specifically in versions through 1.2.4. The issue arises from a lack of proper capability checks in the 'hs_update_ai_chat_settings()' and 'hive_lite_support_get_all_binbox()' functions. This flaw allows authenticated attackers with Subscriber-level access or higher to unauthorized access and modification of data. Exploitation could lead to unauthorized reading and overwriting of the site's OpenAI API key, inspection data, and AI chat prompts and behavior.
No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 6, 2025CISA-ADP
Assessed Jun 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Hive Support | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | CVE Modified | [email protected] |
| Jun 6, 2025 | New CVE Received | [email protected] |
Volerion