Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-68023
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68023 is a Missing Authorization vulnerability in the Addonify – Compare Products For WooCommerce WordPress plugin that allows unauthenticated attackers to perform unauthorized settings changes. It affects all versions up to and including 1.1.17, with version 1.1.18 containing the fix. The vulnerability was reported on November 22, 2025, and published on February 4, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Feedly).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before processing certain settings-related actions (Patchstack). The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The vulnerability falls under OWASP Top 10 category A1: Broken Access Control, and exploitation allows incorrectly configured access control security levels to be abused to modify plugin settings (Patchstack).

Impact

Successful exploitation allows unauthenticated remote attackers to modify plugin settings on affected WooCommerce sites, resulting in low integrity and low availability impact with no confidentiality impact (Feedly). While the direct impact is limited to settings manipulation, unauthorized configuration changes could disrupt the product comparison functionality, degrade the shopping experience, or potentially be chained with other vulnerabilities for broader site compromise. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been specifically reported for CVE-2025-68023. The EPSS score is very low at approximately 0.017%, indicating a low near-term probability of exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack has issued a virtual patch/mitigation rule to block exploitation attempts for users of its platform (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Addonify – Compare Products For WooCommerce plugin at version 1.1.17 or earlier using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files.
  2. Identify vulnerable endpoint: Locate the plugin's AJAX or REST API endpoint responsible for updating plugin settings, which lacks proper capability/nonce checks.
  3. Craft unauthorized request: Send a crafted HTTP POST request to the vulnerable endpoint without any authentication credentials, including the desired settings values as parameters.
  4. Modify plugin settings: The server processes the request without authorization checks, applying the attacker-supplied settings changes to the plugin configuration.
  5. Achieve objective: Depending on the settings modified, the attacker may disrupt the compare products functionality, alter display behavior, or set the stage for further exploitation (Patchstack).

Indicators of compromise

  • Network: Unexpected POST requests to WordPress AJAX endpoints (/wp-admin/admin-ajax.php) or REST API routes associated with the addonify-compare-products plugin from unauthenticated sources.
  • Logs: WordPress access logs showing unauthenticated requests to plugin-specific action handlers with settings-related parameters; repeated requests from the same IP targeting plugin endpoints.
  • File System: Unexpected changes to plugin option values stored in the WordPress wp_options table, particularly options prefixed with addonify_compare_ or similar plugin-specific keys.
  • Database: Audit of wp_options table for unexpected modifications to Addonify Compare Products settings entries at unusual times or from unexpected sources.

Mitigation and workarounds

The vendor has released version 1.1.18 of the Addonify – Compare Products For WooCommerce plugin, which resolves this vulnerability. Site administrators should update the plugin to version 1.1.18 or later immediately via the WordPress admin dashboard or the WordPress plugin repository. Patchstack users benefit from an automatically deployed virtual patch/mitigation rule that blocks exploitation attempts until the plugin is updated (Patchstack). If immediate update is not possible, restricting access to WordPress AJAX endpoints via a web application firewall (WAF) is a recommended interim measure.

Community reactions

The vulnerability was discovered and reported by security researcher Legion Hunter on November 22, 2025, and disclosed by Patchstack on February 4, 2026 (Patchstack). Wordfence included it in their weekly WordPress vulnerability report for the period of February 2–8, 2026 (Wordfence). No significant broader media coverage or notable social media discussion has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85009MEDIUM6.5
  • restropress
NoNoSep 16, 2026
CVE-2026-85010MEDIUM5.3
  • restropress
NoYesSep 16, 2026
CVE-2026-86475MEDIUM5.3
  • appointment-hour-booking
NoYesSep 16, 2026
CVE-2026-84906MEDIUM5.3
  • wp-event-solution
NoYesSep 16, 2026
CVE-2026-16557MEDIUM4.3
  • nimble-builder
NoNoSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management