CVE-2025-64282: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64282 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the RadiusTheme Radius Blocks WordPress plugin. It affects all versions through 2.2.1 and was reported on January 13, 2025 by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity), with public disclosure by Patchstack on March 31, 2025. The vulnerability has a CVSS v3.1 base score of 4.3 (Medium), requiring low privileges and no user interaction (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), corresponding to OWASP Top 10 category A1: Broken Access Control. The plugin fails to properly validate that a requesting user is authorized to access specific objects, allowing an attacker to manipulate user-controlled keys (e.g., object IDs in requests) to reference resources they should not have access to. Exploitation requires only a low-privilege authenticated account (Subscriber level) and network access, with no special conditions or user interaction needed (Patchstack).

Impact

Successful exploitation allows an authenticated attacker with subscriber-level access to bypass authorization controls and read sensitive application data they are not permitted to access, resulting in a limited confidentiality impact. There is no integrity or availability impact associated with this vulnerability. The scope is limited to the affected WordPress installation, and while the individual impact is low, Patchstack notes that IDOR-class vulnerabilities are commonly leveraged in mass-exploit campaigns targeting large numbers of WordPress sites simultaneously (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. Patchstack classifies the priority as Low, noting the issue is unlikely to be exploited. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack, Red Hat CVE).

Exploitation steps

  1. Authentication: Log in to the target WordPress site with a low-privilege account (e.g., Subscriber role).
  2. Identify vulnerable endpoints: Enumerate plugin-specific REST API endpoints or AJAX actions registered by the Radius Blocks plugin that accept object identifiers as parameters.
  3. Manipulate object references: Modify the user-controlled key (e.g., post ID, block ID, or similar parameter) in requests to reference objects belonging to other users or restricted content.
  4. Extract sensitive data: Observe the server response for unauthorized data disclosure, such as draft posts, private content, or other restricted application data (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated requests (Subscriber-level user) to Radius Blocks plugin endpoints with sequentially or randomly enumerated object ID parameters.
  • Logs: Repeated access to the same plugin endpoint with varying ID values from a single authenticated session, suggesting automated enumeration.
  • Network: Unusual volume of authenticated API or AJAX requests to /wp-admin/admin-ajax.php or REST API routes associated with the radius-blocks plugin from a single low-privilege user account.

Mitigation and workarounds

As of the time of disclosure, no official patch from RadiusTheme was available for versions through 2.2.1. Site administrators should monitor the RadiusTheme plugin repository for an updated version that addresses this vulnerability and upgrade as soon as one is released. In the interim, consider using a WordPress security plugin such as Patchstack (which offers virtual patching), restricting Subscriber-level user registration if not required, or temporarily deactivating the Radius Blocks plugin if the functionality is non-essential (Patchstack).

Community reactions

The vulnerability received limited public attention, consistent with its low severity rating. Patchstack, the assigning CNA, classified it as low priority with no impactful threat, and the disclosure was routine. No notable researcher commentary, vendor statements beyond the Patchstack advisory, or significant media coverage has been identified (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management