
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67468 is a Missing Authorization (Broken Access Control) vulnerability in the CRM Perks plugin "Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms" for WordPress. It affects all plugin versions up to and including 1.4.6, and was reported by researcher Nabil Irawan on November 8, 2025, with public disclosure on December 8–9, 2025. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), requiring low privileges (Subscriber level) and no user interaction (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization, authentication, or nonce token checks on one or more functions (Patchstack). This allows a low-privileged authenticated user (e.g., a WordPress Subscriber) to invoke functions that should be restricted to higher-privileged roles, exploiting incorrectly configured access control security levels. The attack vector is network-based, requires low complexity, and no user interaction beyond the attacker's own authentication (Feedly). No public proof-of-concept code has been identified at this time.
Successful exploitation allows a low-privileged authenticated attacker to perform unauthorized actions within the plugin's functionality, primarily resulting in a low confidentiality impact with no integrity or availability impact per the CVSS scoring (Patchstack). This could expose Salesforce integration settings or form submission data to unauthorized users. The scope is limited to the affected WordPress site and does not indicate a path to full system compromise or lateral movement.
No active in-the-wild exploitation has been reported for CVE-2025-67468, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is very low at approximately 0.017%, indicating a low probability of exploitation in the near term (Feedly). Patchstack classifies this as low priority with no impactful threat, though they note that vulnerabilities of this class can be used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack). No exploit kits or threat actor attribution have been identified.
The vendor has released version 1.4.7 of the "Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms" plugin, which patches this vulnerability. WordPress site administrators should update the plugin to version 1.4.7 or later immediately (Patchstack). Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. If an immediate update is not possible, restricting Subscriber-level user registration on the WordPress site can reduce the attack surface.
Patchstack, which coordinated the disclosure, classifies this as a low-priority issue with no impactful threat, noting it is unlikely to be exploited despite the class of vulnerability being associated with mass-exploit campaigns (Patchstack). No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."