
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68036 is a Missing Authorization (Broken Access Control) vulnerability in the CubeWP WordPress plugin (cubewp-framework) that allows unauthenticated remote attackers to access functionality not properly constrained by ACLs. It affects CubeWP versions up to and including 1.1.27, with version 1.1.28 containing the fix. The vulnerability was reported on September 16, 2025, by researcher MD ISMAIL and published by Patchstack on December 26–29, 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack, Red Hat CVE).
The root cause is CWE-862 (Missing Authorization) — the plugin fails to perform adequate authorization or nonce token checks on one or more functions, allowing unauthenticated users to invoke privileged actions. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable remotely. This class of vulnerability in WordPress plugins typically manifests as AJAX handlers or REST API endpoints registered without capability checks, enabling any visitor to trigger restricted functionality. The vulnerability is classified under OWASP Top 10 A1: Broken Access Control (Patchstack).
Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning attackers can access sensitive data or restricted plugin functionality without authorization. Because no privileges are required, any unauthenticated visitor to a vulnerable WordPress site can trigger the flaw, potentially exposing site configuration, user data, or other protected content managed by the CubeWP framework. The scope is limited to the affected system, but the ease of exploitation makes it suitable for mass-exploit campaigns targeting WordPress installations at scale (Patchstack).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.032% (0.000320), indicating a low current probability of exploitation in the wild. Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress plugins regardless of site popularity. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has issued a virtual patch (mitigation rule) for its users (Patchstack).
/wp-content/plugins/cubewp-framework/ paths on target sites.wp-admin/admin-ajax.php?action=<cubewp_action>) without any authentication cookies or tokens.wp-admin/admin-ajax.php or REST API endpoints associated with CubeWP plugin actions from unknown or automated IP addresses; high-volume repeated requests to these endpoints suggesting scanning or mass exploitation.admin-ajax.php with CubeWP-specific action parameters from unauthenticated sessions (no valid session cookies); unexpected 200 responses to these requests from non-logged-in users.The primary remediation is to update the CubeWP plugin (cubewp-framework) to version 1.1.28 or later, which contains the fix for this vulnerability. Site administrators unable to update immediately should consider using Patchstack's virtual patching feature, which provides a mitigation rule to block exploitation attempts until the plugin is updated. Restricting access to WordPress admin AJAX endpoints via WAF rules or firewall policies for unauthenticated users can also reduce exposure as a temporary measure (Patchstack).
The vulnerability was reported by security researcher MD ISMAIL through Patchstack's responsible disclosure program and published in late December 2025. Patchstack classified it as high priority, warning that broken access control vulnerabilities in WordPress plugins are frequently leveraged in mass-exploit campaigns. The disclosure received limited but notable social media coverage, including posts on Mastodon and Bluesky from security-focused accounts (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."