
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68088 is a Missing Authorization (Broken Access Control) vulnerability in the Huger for Elementor WordPress plugin by merkulove. It allows authenticated attackers with low privileges (Subscriber-level) to exploit incorrectly configured access control security levels. All versions up to and including 1.1.5 are affected, and no official patch was available at the time of disclosure. The vulnerability was reported by researcher Phat RiO on November 11, 2025, and published on December 16, 2025, with a CVSS v3.1 base score of 5.4 (Medium) (Patchstack, NVD).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to perform adequate authorization checks on one or more functions, allowing lower-privileged users to invoke actions intended for higher-privileged roles. Exploitation requires only a valid low-privilege account (e.g., Subscriber) and network access to the target WordPress site; no user interaction is needed. The attack vector is network-based with low attack complexity, meaning an authenticated attacker can directly send crafted requests to the vulnerable plugin endpoints without special conditions (Patchstack, NVD).
Successful exploitation results in limited but meaningful confidentiality and integrity impacts — an attacker with Subscriber-level access can read data or perform actions beyond their intended privilege level. Availability is not impacted. The vulnerability could be leveraged in mass-exploit campaigns targeting WordPress sites at scale, regardless of site size or popularity, as noted by Patchstack (Patchstack).
As of the disclosure date, no official patched version of the Huger for Elementor plugin was available. Site administrators should remove or deactivate the plugin until a patched version is released. If removal is not feasible, restricting user registration and limiting Subscriber-level account creation can reduce the attack surface. Monitoring for unexpected actions performed by low-privilege accounts is also advisable (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."