CVE-2025-68069: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68069 is a Missing Authorization (Broken Access Control) vulnerability in the wpWax Directorist WordPress plugin. It allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels, potentially modifying data they should not have access to. The vulnerability affects Directorist versions from the beginning through 8.6.6 (inclusive). It was published on February 20, 2026, and carries a CVSS v3.1 base score of 7.1 (High) (Feedly).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the appropriate permissions before performing sensitive operations. The attack vector is network-based, requires low privileges (an authenticated user account), and no user interaction, making it straightforward to exploit once an attacker has any level of authenticated access to the WordPress site. The vulnerability falls under the category of Broken Access Control, where improperly configured access control levels allow lower-privileged users to perform actions reserved for higher-privileged roles (Feedly, Patchstack).

Impact

Successful exploitation results in a high integrity impact and low confidentiality impact, with no availability impact. An authenticated low-privileged attacker can manipulate or modify data within the Directorist plugin that should be restricted to higher-privileged users (e.g., administrators or editors), potentially altering directory listings, business entries, or plugin configurations. While the scope is unchanged (limited to the affected system), unauthorized data modification could undermine the integrity of directory content managed by the plugin (Feedly).

Exploitability

The EPSS score for CVE-2025-68069 is approximately 0.017% (0.000170), indicating a low probability of exploitation in the wild at this time. No public proof-of-concept exploit code, active in-the-wild exploitation, or threat actor attribution has been reported. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and minimal privilege requirement (any authenticated user) make it relatively easy to exploit if an attacker has even a basic account on the target WordPress site (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Directorist plugin version 8.6.6 or earlier using tools like WPScan, Shodan, or by inspecting publicly accessible WordPress plugin metadata.
  2. Obtain Low-Privileged Access: Register or obtain any authenticated account on the target WordPress site (e.g., a subscriber or contributor account), as the vulnerability requires only low privileges.
  3. Identify Vulnerable Endpoints: Enumerate Directorist plugin REST API endpoints or admin-ajax actions that lack proper authorization checks, which would normally be restricted to higher-privileged roles.
  4. Send Unauthorized Request: Craft and send HTTP requests (e.g., POST to a Directorist AJAX action or REST endpoint) that perform privileged operations such as modifying directory listings, business entries, or plugin settings, without the required capability checks.
  5. Achieve Unauthorized Data Modification: The server processes the request without verifying the user's authorization level, resulting in unauthorized modification of Directorist plugin data (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated low-privileged users (subscribers/contributors) making POST requests to Directorist-specific admin-ajax endpoints (/wp-admin/admin-ajax.php) or REST API routes (/wp-json/directorist/) that are typically reserved for administrators.
  • Logs: Unexpected modifications to Directorist directory listings, business entries, or plugin settings in the WordPress database audit logs or activity logs (if a logging plugin is installed).
  • Network: Repeated or scripted HTTP POST requests from a single authenticated session targeting Directorist plugin endpoints with unusual parameters.
  • File System: Unexpected changes to Directorist plugin configuration files or database entries reflecting unauthorized modifications to directory content.

Mitigation and workarounds

Users should update the Directorist plugin to a version beyond 8.6.6 that includes the authorization fix — check the official WordPress plugin repository or wpWax for the latest patched release. If an immediate update is not possible, site administrators should restrict user registration or limit the roles that can interact with Directorist plugin functionality as a temporary workaround. Implementing a Web Application Firewall (WAF) with WordPress-specific rules (e.g., Wordfence or Patchstack) can also help detect and block unauthorized access attempts against plugin endpoints (Feedly, Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management