CVE-2025-67468
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67468 is a Missing Authorization (Broken Access Control) vulnerability in the CRM Perks plugin "Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms" for WordPress. It affects all plugin versions up to and including 1.4.6, and was reported by researcher Nabil Irawan on November 8, 2025, with public disclosure on December 8–9, 2025. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), requiring low privileges (Subscriber level) and no user interaction (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization, authentication, or nonce token checks on one or more functions (Patchstack). This allows a low-privileged authenticated user (e.g., a WordPress Subscriber) to invoke functions that should be restricted to higher-privileged roles, exploiting incorrectly configured access control security levels. The attack vector is network-based, requires low complexity, and no user interaction beyond the attacker's own authentication (Feedly). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation allows a low-privileged authenticated attacker to perform unauthorized actions within the plugin's functionality, primarily resulting in a low confidentiality impact with no integrity or availability impact per the CVSS scoring (Patchstack). This could expose Salesforce integration settings or form submission data to unauthorized users. The scope is limited to the affected WordPress site and does not indicate a path to full system compromise or lateral movement.

Exploitability

No active in-the-wild exploitation has been reported for CVE-2025-67468, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is very low at approximately 0.017%, indicating a low probability of exploitation in the near term (Feedly). Patchstack classifies this as low priority with no impactful threat, though they note that vulnerabilities of this class can be used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack). No exploit kits or threat actor attribution have been identified.

Mitigation and workarounds

The vendor has released version 1.4.7 of the "Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms" plugin, which patches this vulnerability. WordPress site administrators should update the plugin to version 1.4.7 or later immediately (Patchstack). Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard. If an immediate update is not possible, restricting Subscriber-level user registration on the WordPress site can reduce the attack surface.

Community reactions

Patchstack, which coordinated the disclosure, classifies this as a low-priority issue with no impactful threat, noting it is unlikely to be exploited despite the class of vulnerability being associated with mass-exploit campaigns (Patchstack). No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-17087HIGH7.5
  • wp-travel-engine
NoYesAug 16, 2026
CVE-2026-2497HIGH7.2
  • gallery-plugin
NoYesAug 16, 2026
CVE-2026-17608MEDIUM6.5
  • wp-compress-image-optimizer
NoYesAug 16, 2026
CVE-2026-2357MEDIUM6.4
  • bold-page-builder
NoYesAug 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management