CVE-2026-25367 | NooTheme CitiLights Plugin up to 3.7.2 on WordPress authorization
A vulnerability has been found in NooTheme CitiLights Plugin up to 3.7.2 on WordPress and classified as critical. This affects an unknown function. This manipulation causes missing authorization.
This vulnerability appears as CVE-2026-25367. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.