CVE-2025-68003
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68003 is a Missing Authorization vulnerability in the WordPress plugin "Shown Connector" (by renatoatshown) that allows unauthenticated attackers to exploit incorrectly configured access control security levels, resulting in unauthorized settings changes. It affects all versions of the plugin through 1.2.10, with no official patch available as of the time of disclosure. The vulnerability was reported by researcher Legion Hunter on October 18, 2025, and published by Patchstack on January 15–22, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Patchstack (Patchstack).

Technical details

The root cause is CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before allowing access to sensitive functionality. This allows unauthenticated network-based attackers (no privileges or user interaction required) to modify plugin settings, exploiting incorrectly configured access control security levels. The attack vector is network-accessible, with low complexity, making it straightforward to exploit at scale (Patchstack).

Impact

Successful exploitation allows unauthenticated attackers to modify plugin settings on affected WordPress installations, impacting both integrity and availability (low impact each) with no direct confidentiality exposure per the CVSS assessment. This type of settings-change vulnerability is commonly leveraged in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity, potentially enabling further abuse such as injecting malicious content or disrupting site functionality (Patchstack).

Exploitability

No official patch is available, and Patchstack has issued a virtual mitigation rule to block exploitation attempts. The EPSS score is approximately 0.017% (0.000170), indicating a low but non-zero probability of exploitation in the near term. No in-the-wild exploitation or threat actor attribution has been publicly reported. Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns against WordPress sites (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Shown Connector plugin (version ≤ 1.2.10) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at /wp-content/plugins/shown-connector/readme.txt.
  2. Identify vulnerable endpoint: Locate the plugin's settings-handling endpoint or REST API route that lacks proper authorization checks (specific endpoint details are not publicly disclosed).
  3. Craft unauthenticated request: Send an HTTP request (e.g., POST) to the vulnerable endpoint without authentication credentials, including desired settings values as parameters.
  4. Modify plugin settings: The server processes the request without verifying user permissions, applying the attacker-supplied settings changes to the plugin configuration.
  5. Achieve objective: Depending on the plugin's functionality, modified settings could be used to inject content, redirect traffic, or disrupt site behavior (Patchstack).

Indicators of compromise

  • Network: Unexpected unauthenticated POST requests to WordPress admin-ajax endpoints or REST API routes associated with the Shown Connector plugin from unknown IP addresses.
  • Logs: WordPress access logs showing repeated requests to plugin-specific endpoints without valid authentication cookies or nonces; unusual modification timestamps on plugin option records in the WordPress database.
  • File System: Unexpected changes to plugin configuration files or WordPress options table entries related to shown-connector settings.
  • Application: Unexplained changes to Shown Connector plugin settings visible in the WordPress admin dashboard (Patchstack).

Mitigation and workarounds

No official patch from the plugin developer is available for versions through 1.2.10. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators are advised to deactivate and remove the Shown Connector plugin until a patched version is available, or use a web application firewall (WAF) solution such as Patchstack to apply the mitigation rule. Contacting the plugin developer or hosting provider for assistance is also recommended (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16145HIGH7.2
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026
CVE-2026-18387MEDIUM6.5
  • groundhogg
NoYesAug 15, 2026
CVE-2026-16586MEDIUM6.5
  • contest-gallery
NoYesAug 15, 2026
CVE-2026-17090MEDIUM6.4
  • beaver-builder-lite-version
NoYesAug 15, 2026
CVE-2026-16146MEDIUM4.9
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management