
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68069 is a Missing Authorization (Broken Access Control) vulnerability in the wpWax Directorist WordPress plugin. It allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels, potentially modifying data they should not have access to. The vulnerability affects Directorist versions from the beginning through 8.6.6 (inclusive). It was published on February 20, 2026, and carries a CVSS v3.1 base score of 7.1 (High) (Feedly).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the appropriate permissions before performing sensitive operations. The attack vector is network-based, requires low privileges (an authenticated user account), and no user interaction, making it straightforward to exploit once an attacker has any level of authenticated access to the WordPress site. The vulnerability falls under the category of Broken Access Control, where improperly configured access control levels allow lower-privileged users to perform actions reserved for higher-privileged roles (Feedly, Patchstack).
Successful exploitation results in a high integrity impact and low confidentiality impact, with no availability impact. An authenticated low-privileged attacker can manipulate or modify data within the Directorist plugin that should be restricted to higher-privileged users (e.g., administrators or editors), potentially altering directory listings, business entries, or plugin configurations. While the scope is unchanged (limited to the affected system), unauthorized data modification could undermine the integrity of directory content managed by the plugin (Feedly).
The EPSS score for CVE-2025-68069 is approximately 0.017% (0.000170), indicating a low probability of exploitation in the wild at this time. No public proof-of-concept exploit code, active in-the-wild exploitation, or threat actor attribution has been reported. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and minimal privilege requirement (any authenticated user) make it relatively easy to exploit if an attacker has even a basic account on the target WordPress site (Feedly).
/wp-admin/admin-ajax.php) or REST API routes (/wp-json/directorist/) that are typically reserved for administrators.Users should update the Directorist plugin to a version beyond 8.6.6 that includes the authorization fix — check the official WordPress plugin repository or wpWax for the latest patched release. If an immediate update is not possible, site administrators should restrict user registration or limit the roles that can interact with Directorist plugin functionality as a temporary workaround. Implementing a Web Application Firewall (WAF) with WordPress-specific rules (e.g., Wordfence or Patchstack) can also help detect and block unauthorized access attempts against plugin endpoints (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."