
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68572 is a Missing Authorization vulnerability in the Spider Themes BBP Core WordPress plugin (bbp-core) that allows authenticated low-privilege attackers to exploit incorrectly configured access control security levels. It affects BBP Core versions from n/a through 1.4.1 (inclusive). The vulnerability was published on December 24, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 8.8 (High) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before granting access to restricted functionality or resources. An attacker with a low-privilege WordPress account (e.g., a subscriber) can send crafted network requests to exploit incorrectly configured access control checks within the plugin, bypassing intended role-based restrictions. No special conditions or user interaction are required beyond having a valid low-privilege account on the target WordPress site (Feedly).
Successful exploitation grants a low-privilege attacker high impact across confidentiality, integrity, and availability of the affected WordPress installation. An attacker could gain unauthorized access to sensitive data, modify or delete content, and potentially disrupt site availability — all without elevated permissions. The scope is limited to the affected system, but the breadth of impact makes this a significant risk for any WordPress site running the vulnerable BBP Core plugin (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039%, indicating a low probability of exploitation in the near term. The vulnerability was reported and assigned by Patchstack (Feedly).
The primary remediation is to update the BBP Core plugin to a version newer than 1.4.1. If an immediate update is not possible, administrators should consider temporarily deactivating the plugin, implementing strict role-based access controls, and monitoring WordPress access logs for suspicious unauthorized access attempts. A thorough review of user roles and capabilities on the affected WordPress site is also recommended (Feedly, Patchstack).
The vulnerability received brief coverage from automated security news aggregators such as The Hacker Wire and was noted on social platforms including Mastodon and Bluesky shortly after disclosure. No significant researcher commentary or vendor statements beyond the Patchstack advisory have been identified (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."