CVE-2025-68026
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68026 is a Missing Authorization vulnerability in the LC Wizard (ghl-wizard) WordPress plugin that allows unauthenticated attackers to exploit incorrectly configured access control security levels, resulting in unauthorized settings changes. It affects all versions of the plugin up to and including 2.1.1, with version 2.1.2 containing the fix. The vulnerability was reported on November 22, 2025, and published on February 5, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Feedly).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before allowing access to sensitive functionality. An unauthenticated remote attacker can send crafted network requests to plugin endpoints that lack proper capability checks, enabling unauthorized modification of plugin settings. No user interaction is required, and the attack complexity is low, making it straightforward to exploit over the network (Patchstack, Feedly).

Impact

Successful exploitation allows unauthenticated attackers to modify plugin settings on affected WordPress sites, impacting both integrity and availability (CVSS scores: Integrity: Low, Availability: Low). While there is no direct confidentiality impact, unauthorized settings changes could disrupt site functionality, alter integration configurations (such as GoHighLevel CRM connections managed by LC Wizard), or facilitate further attacks. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.017% (0.000170), indicating a low current probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as medium priority and notes that missing authorization vulnerabilities in WordPress plugins are frequently targeted in automated mass-exploit campaigns (Patchstack, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the LC Wizard (ghl-wizard) plugin version 2.1.1 or earlier using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files at /wp-content/plugins/ghl-wizard/readme.txt.
  2. Identify vulnerable endpoints: Enumerate plugin AJAX actions or REST API endpoints registered by LC Wizard that handle settings updates but lack proper capability checks (e.g., wp_ajax_nopriv_ hooks or unprotected REST routes).
  3. Craft malicious request: Send an unauthenticated HTTP POST or GET request to the identified endpoint with parameters designed to modify plugin settings (e.g., API keys, integration URLs, or configuration values).
  4. Achieve unauthorized settings change: The server processes the request without verifying user permissions, applying the attacker-supplied settings — potentially disrupting CRM integrations, redirecting data, or enabling further compromise of the WordPress site (Patchstack).

Indicators of compromise

  • Network: Unexpected unauthenticated POST requests to WordPress AJAX endpoints (/wp-admin/admin-ajax.php) or REST API routes associated with the ghl-wizard plugin from unknown or automated IP addresses.
  • Logs: WordPress access logs showing repeated requests to plugin-specific action handlers without valid authentication cookies or nonces; unusual activity in wp-login.php or admin-ajax.php from non-admin IPs.
  • File System: Unexpected changes to LC Wizard plugin option values in the WordPress database (wp_options table entries prefixed with plugin-specific keys); review for altered API keys or endpoint URLs.
  • Process: Sudden changes in GoHighLevel CRM integration behavior or unexpected data routing that may indicate tampered plugin configuration (Patchstack).

Mitigation and workarounds

The vendor has released version 2.1.2 of the LC Wizard plugin, which patches this vulnerability. Site administrators should update to version 2.1.2 or later immediately via the WordPress plugin dashboard. As a temporary workaround for those unable to update, Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts for Patchstack-protected sites. If neither option is available, consider deactivating the plugin until an update can be applied (Patchstack).

Community reactions

The vulnerability was discovered and reported by security researcher "Legion Hunter" through Patchstack's coordinated disclosure process on November 22, 2025, and was publicly disclosed on February 5, 2026. Wordfence included it in their weekly WordPress vulnerability intelligence report for the period of February 2–8, 2026. No significant broader media coverage or notable social media commentary has been identified beyond standard vulnerability database listings (Wordfence, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management