CVE-2025-68086
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68086 is a Missing Authorization (Broken Access Control) vulnerability in the Reformer for Elementor WordPress plugin developed by merkulove. It allows authenticated attackers with low privileges (e.g., Subscriber-level) to exploit incorrectly configured access control security levels, potentially performing actions beyond their intended permissions. All versions up to and including 1.0.6 are affected. The vulnerability was reported by researcher Phat RiO on November 11, 2025, and publicly disclosed on December 16, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium) (Patchstack, NVD).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has the necessary permissions before executing certain privileged actions. This falls under OWASP Top 10 category A1: Broken Access Control. Exploitation requires a network-accessible WordPress installation and a low-privilege authenticated account (Subscriber level or above), with no user interaction required and low attack complexity. No public proof-of-concept exploit code has been identified at this time (Patchstack).

Impact

Successful exploitation results in limited but meaningful unauthorized access: an attacker with a low-privilege WordPress account can read restricted data (low confidentiality impact) and modify data or settings they should not have access to (low integrity impact). Availability is not affected. While the individual impact per site is moderate, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or popularity (Patchstack).

Exploitability

No active in-the-wild exploitation has been confirmed, and no public exploit code is known to be available. The EPSS score is very low at approximately 0.017%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority, noting it is unlikely to be exploited in targeted attacks, though mass-exploit campaigns against WordPress plugins remain a general concern (Patchstack, NVD).

Mitigation and workarounds

As of the disclosure date, no official patched version of the Reformer for Elementor plugin has been released. The primary recommended action is to deactivate and remove the plugin until a patched version becomes available. Site administrators unable to remove the plugin should consult their hosting provider or web developer for assistance. Monitoring for unexpected actions performed by low-privilege user accounts (e.g., Subscribers) on the WordPress site may help detect potential abuse (Patchstack).

Community reactions

The vulnerability was discovered and reported by security researcher Phat RiO through Patchstack's Vulnerability Disclosure Program (VDP) on November 11, 2025. Patchstack assigned it a low priority rating, noting limited exploitability and impact. No significant broader media coverage or notable researcher commentary beyond the initial Patchstack disclosure has been identified (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16145HIGH7.2
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026
CVE-2026-18387MEDIUM6.5
  • groundhogg
NoYesAug 15, 2026
CVE-2026-16586MEDIUM6.5
  • contest-gallery
NoYesAug 15, 2026
CVE-2026-17090MEDIUM6.4
  • beaver-builder-lite-version
NoYesAug 15, 2026
CVE-2026-16146MEDIUM4.9
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management