
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68026 is a Missing Authorization vulnerability in the LC Wizard (ghl-wizard) WordPress plugin that allows unauthenticated attackers to exploit incorrectly configured access control security levels, resulting in unauthorized settings changes. It affects all versions of the plugin up to and including 2.1.1, with version 2.1.2 containing the fix. The vulnerability was reported on November 22, 2025, and published on February 5, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Feedly).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before allowing access to sensitive functionality. An unauthenticated remote attacker can send crafted network requests to plugin endpoints that lack proper capability checks, enabling unauthorized modification of plugin settings. No user interaction is required, and the attack complexity is low, making it straightforward to exploit over the network (Patchstack, Feedly).
Successful exploitation allows unauthenticated attackers to modify plugin settings on affected WordPress sites, impacting both integrity and availability (CVSS scores: Integrity: Low, Availability: Low). While there is no direct confidentiality impact, unauthorized settings changes could disrupt site functionality, alter integration configurations (such as GoHighLevel CRM connections managed by LC Wizard), or facilitate further attacks. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity (Patchstack).
No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.017% (0.000170), indicating a low current probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as medium priority and notes that missing authorization vulnerabilities in WordPress plugins are frequently targeted in automated mass-exploit campaigns (Patchstack, Feedly).
/wp-content/plugins/ghl-wizard/readme.txt.wp_ajax_nopriv_ hooks or unprotected REST routes)./wp-admin/admin-ajax.php) or REST API routes associated with the ghl-wizard plugin from unknown or automated IP addresses.wp-login.php or admin-ajax.php from non-admin IPs.wp_options table entries prefixed with plugin-specific keys); review for altered API keys or endpoint URLs.The vendor has released version 2.1.2 of the LC Wizard plugin, which patches this vulnerability. Site administrators should update to version 2.1.2 or later immediately via the WordPress plugin dashboard. As a temporary workaround for those unable to update, Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts for Patchstack-protected sites. If neither option is available, consider deactivating the plugin until an update can be applied (Patchstack).
The vulnerability was discovered and reported by security researcher "Legion Hunter" through Patchstack's coordinated disclosure process on November 22, 2025, and was publicly disclosed on February 5, 2026. Wordfence included it in their weekly WordPress vulnerability intelligence report for the period of February 2–8, 2026. No significant broader media coverage or notable social media commentary has been identified beyond standard vulnerability database listings (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."