
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68023 is a Missing Authorization vulnerability in the Addonify – Compare Products For WooCommerce WordPress plugin that allows unauthenticated attackers to perform unauthorized settings changes. It affects all versions up to and including 1.1.17, with version 1.1.18 containing the fix. The vulnerability was reported on November 22, 2025, and published on February 4, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Feedly).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before processing certain settings-related actions (Patchstack). The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The vulnerability falls under OWASP Top 10 category A1: Broken Access Control, and exploitation allows incorrectly configured access control security levels to be abused to modify plugin settings (Patchstack).
Successful exploitation allows unauthenticated remote attackers to modify plugin settings on affected WooCommerce sites, resulting in low integrity and low availability impact with no confidentiality impact (Feedly). While the direct impact is limited to settings manipulation, unauthorized configuration changes could disrupt the product comparison functionality, degrade the shopping experience, or potentially be chained with other vulnerabilities for broader site compromise. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack).
No public proof-of-concept exploit code or active in-the-wild exploitation has been specifically reported for CVE-2025-68023. The EPSS score is very low at approximately 0.017%, indicating a low near-term probability of exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack has issued a virtual patch/mitigation rule to block exploitation attempts for users of its platform (Patchstack).
/wp-admin/admin-ajax.php) or REST API routes associated with the addonify-compare-products plugin from unauthenticated sources.wp_options table, particularly options prefixed with addonify_compare_ or similar plugin-specific keys.wp_options table for unexpected modifications to Addonify Compare Products settings entries at unusual times or from unexpected sources.The vendor has released version 1.1.18 of the Addonify – Compare Products For WooCommerce plugin, which resolves this vulnerability. Site administrators should update the plugin to version 1.1.18 or later immediately via the WordPress admin dashboard or the WordPress plugin repository. Patchstack users benefit from an automatically deployed virtual patch/mitigation rule that blocks exploitation attempts until the plugin is updated (Patchstack). If immediate update is not possible, restricting access to WordPress AJAX endpoints via a web application firewall (WAF) is a recommended interim measure.
The vulnerability was discovered and reported by security researcher Legion Hunter on November 22, 2025, and disclosed by Patchstack on February 4, 2026 (Patchstack). Wordfence included it in their weekly WordPress vulnerability report for the period of February 2–8, 2026 (Wordfence). No significant broader media coverage or notable social media discussion has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."