---
id: CVE-2025-11894
title: >-
  The Shelf Planner plugin for WordPress is vulnerable to unauthorized
  modification of data due to a missing capability check on several REST API
  endpoints in all versions up to, and including, 2.8.1
summary: >-
  The Shelf Planner plugin for WordPress is vulnerable to unauthorized
  modification of data due to a missing capability check on several REST API
  endpoints in all versions up to, and including, 2.8.1. This makes it possible
  for unauthentic…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
published: '2025-11-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11894'
references:
  - url: 'https://wordpress.org/plugins/shelf-planner/#developers'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/107031b3-5071-490a-a8f7-060212b1724c?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00273
epssPercentile: 0.18025
ingestedAt: '2026-10-07T21:54:15.009Z'
---

## Overview

The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to modify several of the plugin's settings like the ServerKey and LicenseKey.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
