
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68086 is a Missing Authorization (Broken Access Control) vulnerability in the Reformer for Elementor WordPress plugin developed by merkulove. It allows authenticated attackers with low privileges (e.g., Subscriber-level) to exploit incorrectly configured access control security levels, potentially performing actions beyond their intended permissions. All versions up to and including 1.0.6 are affected. The vulnerability was reported by researcher Phat RiO on November 11, 2025, and publicly disclosed on December 16, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium) (Patchstack, NVD).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has the necessary permissions before executing certain privileged actions. This falls under OWASP Top 10 category A1: Broken Access Control. Exploitation requires a network-accessible WordPress installation and a low-privilege authenticated account (Subscriber level or above), with no user interaction required and low attack complexity. No public proof-of-concept exploit code has been identified at this time (Patchstack).
Successful exploitation results in limited but meaningful unauthorized access: an attacker with a low-privilege WordPress account can read restricted data (low confidentiality impact) and modify data or settings they should not have access to (low integrity impact). Availability is not affected. While the individual impact per site is moderate, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or popularity (Patchstack).
No active in-the-wild exploitation has been confirmed, and no public exploit code is known to be available. The EPSS score is very low at approximately 0.017%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority, noting it is unlikely to be exploited in targeted attacks, though mass-exploit campaigns against WordPress plugins remain a general concern (Patchstack, NVD).
As of the disclosure date, no official patched version of the Reformer for Elementor plugin has been released. The primary recommended action is to deactivate and remove the plugin until a patched version becomes available. Site administrators unable to remove the plugin should consult their hosting provider or web developer for assistance. Monitoring for unexpected actions performed by low-privilege user accounts (e.g., Subscribers) on the WordPress site may help detect potential abuse (Patchstack).
The vulnerability was discovered and reported by security researcher Phat RiO through Patchstack's Vulnerability Disclosure Program (VDP) on November 11, 2025. Patchstack assigned it a low priority rating, noting limited exploitability and impact. No significant broader media coverage or notable researcher commentary beyond the initial Patchstack disclosure has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."