CVE-2025-60152
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60152 is a Missing Authorization (Broken Access Control) vulnerability in the WordPress plugin "Subscribe To Unlock" by wpshuffle, affecting all versions up to and including 1.1.5. The flaw allows authenticated attackers with low privileges (Subscriber-level) to exploit incorrectly configured access control security levels, performing actions beyond their intended permissions. It was reported by João Pedro S Alcântara (Kinorth) on June 6, 2025, and publicly disclosed on September 26, 2025. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Patchstack, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), corresponding to OWASP Top 10 category A1: Broken Access Control. The vulnerability arises from the absence of proper authorization, authentication, or nonce token checks on one or more plugin functions, allowing a low-privileged authenticated user (Subscriber role) to invoke functionality intended for higher-privileged roles. Exploitation occurs over the network with low attack complexity and requires no user interaction, making it straightforward for any authenticated WordPress user to abuse (Patchstack).

Impact

Successful exploitation results in a low integrity impact — an authenticated low-privileged user can perform unauthorized actions within the plugin that should be restricted to higher-privileged roles. There is no direct confidentiality or availability impact. While the individual impact is limited, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or popularity (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified for this vulnerability. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority with unlikely exploitation impact (Patchstack, Red Hat CVE).

Mitigation and workarounds

As of the disclosure date (September 26, 2025), no official patched version of the Subscribe To Unlock plugin is available from the developer. Site administrators should remove or deactivate the plugin until a fix is released. If removal is not feasible, restricting user registration or limiting Subscriber-level accounts on the WordPress site can reduce exposure. Monitoring for unexpected plugin configuration changes may also help detect abuse (Patchstack).

Community reactions

The vulnerability was discovered and disclosed by Patchstack, credited to researcher João Pedro S Alcântara (Kinorth). Patchstack classifies it as low priority with no impactful threat, noting the absence of an official patch. No significant vendor statements, broader media coverage, or notable community discussion have been identified beyond the initial Patchstack advisory (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management