
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68577 is a Missing Authorization (Broken Access Control) vulnerability in the Virusdie WordPress plugin that allows low-privilege authenticated attackers to exploit incorrectly configured access control security levels. It affects all versions of the Virusdie plugin up to and including 1.1.6. The vulnerability was published on December 24, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before granting access to certain functionality or data. An authenticated attacker with low privileges can send crafted network requests to exploit the misconfigured access control, bypassing intended authorization checks. No user interaction is required, and the attack complexity is low, making it straightforward to exploit remotely. No detailed technical write-up or public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation allows a low-privilege authenticated attacker to perform unauthorized actions within the affected WordPress installation, primarily impacting integrity (CVSS integrity impact: Low). An attacker could potentially modify or manipulate data and access sensitive plugin components beyond their authorized scope. Confidentiality and availability are not directly impacted according to the CVSS scoring, but unauthorized access to a security plugin like Virusdie could undermine the overall security posture of the WordPress site (Feedly).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.039%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privilege authenticated account on the target WordPress site, which somewhat limits the attack surface (Feedly).
The primary remediation is to update the Virusdie WordPress plugin to a version newer than 1.1.6. If an immediate update is not possible, administrators should consider temporarily disabling the plugin to reduce exposure. Additionally, reviewing and strengthening access control configurations and monitoring system logs for suspicious unauthorized access attempts are recommended interim measures (Feedly, Patchstack).
The vulnerability received brief social media attention shortly after disclosure, with mentions on Mastodon and Bluesky via TheHackerWire. No significant vendor statements or notable researcher commentary beyond the Patchstack advisory have been identified (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."