CVE-2025-6688
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-6688 is an authentication bypass vulnerability in the Simple Payment plugin for WordPress, affecting versions 1.3.6 through 2.3.8. The flaw allows unauthenticated remote attackers to log in as administrative users due to improper identity verification in the plugin's create_user() function. It was published on June 27, 2025, with a patch released in version 2.3.9. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The create_user() function in the Simple Payment plugin fails to properly verify a user's identity before completing the login process, allowing an unauthenticated attacker to invoke this function and authenticate as an administrator without valid credentials. No user interaction or prior privileges are required, and the attack is conducted entirely over the network with low complexity (Wordfence, WordPress Patch).

Impact

Successful exploitation grants an unauthenticated attacker full administrative access to the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. An attacker could modify or delete website content, install malicious plugins or backdoors, exfiltrate sensitive data (including user credentials and payment information), and use the compromised site as a platform for further attacks such as malware distribution or phishing (Wordfence, Red Hat CVE).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.234%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Simple Payment plugin (versions 1.3.6–2.3.8) using tools like WPScan, Shodan, or by inspecting plugin directories at /wp-content/plugins/simple-payment/.
  2. Locate the vulnerable endpoint: Identify the plugin's endpoint or action that invokes the create_user() function, typically accessible via WordPress AJAX handlers or plugin-specific routes.
  3. Craft a bypass request: Send a crafted HTTP request to the vulnerable endpoint without valid authentication credentials, exploiting the missing identity verification in create_user().
  4. Achieve administrative login: The server processes the request and logs the attacker in as an administrative user, granting full WordPress admin panel access.
  5. Post-exploitation: Install a malicious plugin or web shell, create a persistent backdoor admin account, exfiltrate data, or deface the site (Wordfence, WordPress Patch).

Indicators of compromise

  • Network: Unexpected or repeated unauthenticated HTTP POST requests to WordPress AJAX endpoints (/wp-admin/admin-ajax.php) or plugin-specific routes associated with the Simple Payment plugin; unusual login sessions originating from unknown IP addresses.
  • Logs: WordPress authentication logs (wp-login.php access) showing successful admin logins from unfamiliar IPs or at unusual times; PHP error logs referencing the create_user() function in the Simple Payment plugin.
  • File System: Presence of newly created or modified plugin files in /wp-content/plugins/simple-payment/; unexpected new PHP files (web shells) in the WordPress installation directory.
  • WordPress Admin: Newly created administrator accounts not recognized by site owners; unauthorized changes to site settings, installed plugins, or themes.

Mitigation and workarounds

The vendor released a patch in Simple Payment plugin version 2.3.9, which corrects the identity verification flaw in the create_user() function (WordPress Patch). Site administrators should immediately update the plugin to version 2.3.9 or later via the WordPress admin dashboard. If an immediate update is not possible, temporarily deactivating the plugin is recommended to eliminate the attack surface. Additionally, administrators should audit all WordPress admin accounts for unauthorized additions, review authentication logs for suspicious activity, and consider deploying a Web Application Firewall (WAF) for additional protection (Wordfence).

Community reactions

Wordfence, which discovered and reported the vulnerability, published it in their weekly WordPress vulnerability report for the period of June 23–29, 2025, highlighting it as a critical authentication bypass (Wordfence Blog). Qualys added detection for this CVE in their July 2025 web application detection updates (Qualys). General community reaction has been limited, consistent with the absence of active exploitation at the time of disclosure.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management