CVE-2025-68575
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68575 is a Missing Authorization vulnerability in the Wappointment WordPress plugin (by Wappointment team) that allows attackers with low-privileged access to exploit incorrectly configured access control security levels. It affects Wappointment versions up to and including 2.7.2 (some sources reference up to 2.7.6). The vulnerability was published on December 24, 2025, and assigned a CVSS v3.1 base score of 8.8 (High) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify that an authenticated user has the appropriate permissions before granting access to sensitive functionality or resources. An attacker with a low-privileged WordPress account (e.g., subscriber) can send crafted network requests to restricted plugin endpoints without proper authorization checks, effectively bypassing access controls. No user interaction is required, and the attack is conducted entirely over the network with low complexity (Feedly).

Impact

Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress installation. A low-privileged attacker could gain unauthorized access to sensitive appointment data, modify plugin settings or records, and potentially disrupt service availability. The vulnerability's scope is limited to the affected system, but within that system the attacker can achieve near-complete compromise of the plugin's functionality and associated data (Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039%, indicating a low probability of exploitation in the near term. However, the low attack complexity and minimal privilege requirement (authenticated, low-privilege) make it relatively straightforward to exploit if a PoC becomes available.

Mitigation and workarounds

The primary remediation is to update the Wappointment WordPress plugin to a version newer than 2.7.2 (or 2.7.6 per some sources), which contains the access control fix (Feedly, Patchstack). As interim measures, administrators should review and enforce strict role-based access controls within WordPress, monitor for suspicious unauthorized access attempts to plugin endpoints, and validate user permissions at each critical access point. If the plugin cannot be updated immediately, consider disabling it until a patched version is applied.

Community reactions

The vulnerability received brief coverage on social media platforms including Mastodon (TheHackerWire) and Bluesky shortly after disclosure on December 24, 2025, indicating moderate community awareness (Feedly). No significant vendor statements or notable researcher commentary beyond the Patchstack advisory have been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18603NONEN/A
  • cancel-order-request-woocommerce
NoYesAug 09, 2026
CVE-2026-18473NONEN/A
  • wpdirectorykit
NoYesAug 09, 2026
CVE-2026-18465NONEN/A
  • wp-google-map-gold
NoYesAug 09, 2026
CVE-2026-18464NONEN/A
  • wp-google-map-gold
NoYesAug 09, 2026
CVE-2026-18357NONEN/A
  • wpc-order-tip
NoYesAug 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management