
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68043 is a Missing Authorization (Broken Access Control) vulnerability in the LottieFiles WordPress plugin that allows unauthenticated attackers to exploit incorrectly configured access control security levels. It affects the LottieFiles plugin versions up to and including 3.0.0. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 7.3 (High) (Feedly, Wordfence).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before executing sensitive operations. Because no authentication or privilege check is enforced, a remote, unauthenticated attacker can interact with restricted plugin functionality directly over the network. No complex preconditions are required — the attack vector is network-accessible, requires no user interaction, and no privileges are needed (Feedly). A Nuclei detection template for this vulnerability has been merged into the ProjectDiscovery nuclei-templates repository, indicating public tooling exists for scanning (Nuclei Templates).
Successful exploitation results in low-level impacts across confidentiality, integrity, and availability — an attacker may be able to read sensitive plugin-managed data, modify plugin settings or content, and cause minor disruption to plugin functionality. While the individual impact ratings are low, the lack of any authentication requirement means any internet-exposed WordPress site running the affected plugin version is at risk. The scope is limited to the affected plugin's functionality and does not directly escalate to full server compromise, but unauthorized configuration changes could facilitate further attacks (Feedly).
No confirmed in-the-wild exploitation has been reported as of the available data. The EPSS score is 0.017% (0.000170), indicating a currently low probability of exploitation in the near term. However, a Nuclei template for automated detection of this vulnerability was submitted and merged into the ProjectDiscovery nuclei-templates repository (released in v10.4.1), lowering the barrier for mass scanning (Nuclei Templates). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog based on available information.
wp-admin/admin-ajax.php associated with the LottieFiles plugin from unexpected or unknown IP addresses.wp_options table entries related to lottiefiles).Users should update the LottieFiles WordPress plugin to a version higher than 3.0.0, which addresses the missing authorization checks. Until a patch is applied, site administrators can consider deactivating the plugin entirely to eliminate the attack surface. Restricting access to WordPress REST API endpoints via firewall rules or a Web Application Firewall (WAF) can provide an additional layer of defense (Feedly, Wordfence).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of February 2–8, 2026, highlighting it as part of a broader set of WordPress plugin access control issues (Wordfence). Social media activity on Bluesky from the account beikokucyber.bsky.social referenced the CVE, suggesting some community awareness. The inclusion of a Nuclei detection template in the ProjectDiscovery repository signals recognition from the security research community as a scannable, real-world issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."