
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68575 is a Missing Authorization vulnerability in the Wappointment WordPress plugin (by Wappointment team) that allows attackers with low-privileged access to exploit incorrectly configured access control security levels. It affects Wappointment versions up to and including 2.7.2 (some sources reference up to 2.7.6). The vulnerability was published on December 24, 2025, and assigned a CVSS v3.1 base score of 8.8 (High) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify that an authenticated user has the appropriate permissions before granting access to sensitive functionality or resources. An attacker with a low-privileged WordPress account (e.g., subscriber) can send crafted network requests to restricted plugin endpoints without proper authorization checks, effectively bypassing access controls. No user interaction is required, and the attack is conducted entirely over the network with low complexity (Feedly).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress installation. A low-privileged attacker could gain unauthorized access to sensitive appointment data, modify plugin settings or records, and potentially disrupt service availability. The vulnerability's scope is limited to the affected system, but within that system the attacker can achieve near-complete compromise of the plugin's functionality and associated data (Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039%, indicating a low probability of exploitation in the near term. However, the low attack complexity and minimal privilege requirement (authenticated, low-privilege) make it relatively straightforward to exploit if a PoC becomes available.
The primary remediation is to update the Wappointment WordPress plugin to a version newer than 2.7.2 (or 2.7.6 per some sources), which contains the access control fix (Feedly, Patchstack). As interim measures, administrators should review and enforce strict role-based access controls within WordPress, monitor for suspicious unauthorized access attempts to plugin endpoints, and validate user permissions at each critical access point. If the plugin cannot be updated immediately, consider disabling it until a patched version is applied.
The vulnerability received brief coverage on social media platforms including Mastodon (TheHackerWire) and Bluesky shortly after disclosure on December 24, 2025, indicating moderate community awareness (Feedly). No significant vendor statements or notable researcher commentary beyond the Patchstack advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."