
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68003 is a Missing Authorization vulnerability in the WordPress plugin "Shown Connector" (by renatoatshown) that allows unauthenticated attackers to exploit incorrectly configured access control security levels, resulting in unauthorized settings changes. It affects all versions of the plugin through 1.2.10, with no official patch available as of the time of disclosure. The vulnerability was reported by researcher Legion Hunter on October 18, 2025, and published by Patchstack on January 15–22, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Patchstack (Patchstack).
The root cause is CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before allowing access to sensitive functionality. This allows unauthenticated network-based attackers (no privileges or user interaction required) to modify plugin settings, exploiting incorrectly configured access control security levels. The attack vector is network-accessible, with low complexity, making it straightforward to exploit at scale (Patchstack).
Successful exploitation allows unauthenticated attackers to modify plugin settings on affected WordPress installations, impacting both integrity and availability (low impact each) with no direct confidentiality exposure per the CVSS assessment. This type of settings-change vulnerability is commonly leveraged in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity, potentially enabling further abuse such as injecting malicious content or disrupting site functionality (Patchstack).
No official patch is available, and Patchstack has issued a virtual mitigation rule to block exploitation attempts. The EPSS score is approximately 0.017% (0.000170), indicating a low but non-zero probability of exploitation in the near term. No in-the-wild exploitation or threat actor attribution has been publicly reported. Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns against WordPress sites (Patchstack).
/wp-content/plugins/shown-connector/readme.txt.shown-connector settings.No official patch from the plugin developer is available for versions through 1.2.10. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators are advised to deactivate and remove the Shown Connector plugin until a patched version is available, or use a web application firewall (WAF) solution such as Patchstack to apply the mitigation rule. Contacting the plugin developer or hosting provider for assistance is also recommended (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."