
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6688 is an authentication bypass vulnerability in the Simple Payment plugin for WordPress, affecting versions 1.3.6 through 2.3.8. The flaw allows unauthenticated remote attackers to log in as administrative users due to improper identity verification in the plugin's create_user() function. It was published on June 27, 2025, with a patch released in version 2.3.9. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The create_user() function in the Simple Payment plugin fails to properly verify a user's identity before completing the login process, allowing an unauthenticated attacker to invoke this function and authenticate as an administrator without valid credentials. No user interaction or prior privileges are required, and the attack is conducted entirely over the network with low complexity (Wordfence, WordPress Patch).
Successful exploitation grants an unauthenticated attacker full administrative access to the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. An attacker could modify or delete website content, install malicious plugins or backdoors, exfiltrate sensitive data (including user credentials and payment information), and use the compromised site as a platform for further attacks such as malware distribution or phishing (Wordfence, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Wordfence). The EPSS score is approximately 0.234%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
/wp-content/plugins/simple-payment/.create_user() function, typically accessible via WordPress AJAX handlers or plugin-specific routes.create_user()./wp-admin/admin-ajax.php) or plugin-specific routes associated with the Simple Payment plugin; unusual login sessions originating from unknown IP addresses.wp-login.php access) showing successful admin logins from unfamiliar IPs or at unusual times; PHP error logs referencing the create_user() function in the Simple Payment plugin./wp-content/plugins/simple-payment/; unexpected new PHP files (web shells) in the WordPress installation directory.The vendor released a patch in Simple Payment plugin version 2.3.9, which corrects the identity verification flaw in the create_user() function (WordPress Patch). Site administrators should immediately update the plugin to version 2.3.9 or later via the WordPress admin dashboard. If an immediate update is not possible, temporarily deactivating the plugin is recommended to eliminate the attack surface. Additionally, administrators should audit all WordPress admin accounts for unauthorized additions, review authentication logs for suspicious activity, and consider deploying a Web Application Firewall (WAF) for additional protection (Wordfence).
Wordfence, which discovered and reported the vulnerability, published it in their weekly WordPress vulnerability report for the period of June 23–29, 2025, highlighting it as a critical authentication bypass (Wordfence Blog). Qualys added detection for this CVE in their July 2025 web application detection updates (Qualys). General community reaction has been limited, consistent with the absence of active exploitation at the time of disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."