CVE-2025-60247
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60247 is a Missing Authorization (Broken Access Control) vulnerability in the Bux WooCommerce WordPress plugin that allows unauthenticated attackers to access functionality not properly constrained by ACLs. It affects all versions of the plugin up to and including 1.2.3. The vulnerability was reported on April 18, 2025, and published on May 18, 2025, by Patchstack researcher ch4r0n. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing privileged or sensitive functions. This allows unauthenticated network-based attackers to invoke restricted functionality without any credentials or user interaction. The attack vector is network-accessible, requires low complexity, and no privileges are needed, making it straightforward to exploit remotely (Patchstack).

Impact

Successful exploitation can result in unauthorized modification of site data (integrity impact) and limited disruption of availability, though no confidentiality impact (e.g., data exposure) is expected based on the CVSS assessment. An unauthenticated attacker could perform actions typically reserved for higher-privileged users, potentially altering WooCommerce-related settings or data. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or traffic (Patchstack).

Exploitability

No official patch is currently available for this vulnerability, leaving all sites running Bux WooCommerce ≤ 1.2.3 exposed. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of active exploitation, though the vulnerability class is associated with mass-exploit campaigns. No specific threat actor attribution or confirmed in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA KEV catalog (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Bux WooCommerce plugin (version ≤ 1.2.3) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at /wp-content/plugins/bux-woocommerce/readme.txt.
  2. Identify unprotected endpoints: Enumerate plugin-registered REST API routes or admin-ajax actions that lack capability checks or nonce verification, which are the typical vectors for broken access control in WordPress plugins.
  3. Craft unauthenticated request: Send an HTTP request (GET or POST) directly to the identified unprotected endpoint without authentication headers or cookies, bypassing the expected authorization gate.
  4. Execute privileged action: The missing authorization check allows the request to succeed, enabling the attacker to perform restricted operations such as modifying WooCommerce settings, order data, or other plugin-controlled functionality (Patchstack).

Indicators of compromise

  • Network: Unexpected unauthenticated HTTP requests to WordPress admin-ajax endpoints (/wp-admin/admin-ajax.php) or REST API routes associated with the bux-woocommerce plugin from unknown or automated IP addresses.
  • Logs: WordPress access logs showing repeated POST/GET requests to plugin-specific actions without session cookies or authentication tokens; unusual activity patterns from single IPs targeting plugin endpoints.
  • File System: Unexpected changes to WooCommerce configuration files or plugin data directories under /wp-content/plugins/bux-woocommerce/.
  • Application: Unexplained modifications to WooCommerce orders, settings, or product data without corresponding authenticated user activity in WordPress audit logs.

Mitigation and workarounds

As of the disclosure date, no official patch from the plugin developer is available for Bux WooCommerce. The recommended immediate action is to deactivate and remove the plugin until a patched version is released. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts in the interim. Site administrators should also consider restricting access to WordPress admin and plugin endpoints via web application firewall (WAF) rules (Patchstack).

Community reactions

The vulnerability was discovered and disclosed by security researcher ch4r0n through Patchstack's Vulnerability Disclosure Program (VDP). Patchstack classified it as medium priority and noted the vulnerability class is commonly leveraged in mass-exploit campaigns against WordPress sites. No significant broader media coverage or notable social media commentary has been identified beyond the Patchstack advisory (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15239NONEN/A
  • simple-cloudflare-turnstile
NoYesAug 07, 2026
CVE-2026-15211NONEN/A
  • subscriptions-for-woocommerce
NoYesAug 07, 2026
CVE-2026-15148NONEN/A
  • wp-events-manager
NoYesAug 07, 2026
CVE-2026-16265NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026
CVE-2026-16263NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management