CVE-2025-68088
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68088 is a Missing Authorization (Broken Access Control) vulnerability in the Huger for Elementor WordPress plugin by merkulove. It allows authenticated attackers with low privileges (Subscriber-level) to exploit incorrectly configured access control security levels. All versions up to and including 1.1.5 are affected, and no official patch was available at the time of disclosure. The vulnerability was reported by researcher Phat RiO on November 11, 2025, and published on December 16, 2025, with a CVSS v3.1 base score of 5.4 (Medium) (Patchstack, NVD).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to perform adequate authorization checks on one or more functions, allowing lower-privileged users to invoke actions intended for higher-privileged roles. Exploitation requires only a valid low-privilege account (e.g., Subscriber) and network access to the target WordPress site; no user interaction is needed. The attack vector is network-based with low attack complexity, meaning an authenticated attacker can directly send crafted requests to the vulnerable plugin endpoints without special conditions (Patchstack, NVD).

Impact

Successful exploitation results in limited but meaningful confidentiality and integrity impacts — an attacker with Subscriber-level access can read data or perform actions beyond their intended privilege level. Availability is not impacted. The vulnerability could be leveraged in mass-exploit campaigns targeting WordPress sites at scale, regardless of site size or popularity, as noted by Patchstack (Patchstack).

Mitigation and workarounds

As of the disclosure date, no official patched version of the Huger for Elementor plugin was available. Site administrators should remove or deactivate the plugin until a patched version is released. If removal is not feasible, restricting user registration and limiting Subscriber-level account creation can reduce the attack surface. Monitoring for unexpected actions performed by low-privilege accounts is also advisable (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15991HIGH8.8
  • file-manager
NoYesAug 06, 2026
CVE-2026-15459HIGH8.1
  • wpmudev-updates
NoYesAug 06, 2026
CVE-2026-7529HIGH7.5
  • wisecampaign
NoYesAug 05, 2026
CVE-2026-18325HIGH7.2
  • forminator
NoYesAug 06, 2026
CVE-2026-16636HIGH7.2
  • fluent-smtp
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management