CVE-2025-68581
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68581 is a Missing Authorization vulnerability in the YITHEMES YITH Slider for page builders WordPress plugin that allows low-privilege authenticated attackers to exploit incorrectly configured access control security levels. It affects all versions of the plugin up to and including 1.0.11. The vulnerability was published on December 24, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before granting access to certain functionality. An attacker with a low-privilege WordPress account (e.g., subscriber or contributor) can send crafted network requests to access or manipulate plugin functionality that should be restricted to higher-privileged roles. No special conditions or user interaction are required beyond having a valid low-privilege account on the target WordPress site (Feedly, Patchstack).

Impact

Successful exploitation allows low-privilege authenticated attackers to bypass access controls and potentially view, modify, or delete sensitive plugin data or configurations that should be restricted to administrators. The confidentiality and integrity impacts are both rated Low, with no availability impact, meaning attackers could access or tamper with slider content and settings but are unlikely to cause service disruption. The scope is limited to the affected WordPress installation, with no direct path to lateral movement beyond the site's content management context (Feedly).

Exploitability

There is currently no public proof-of-concept exploit code available, and no evidence of in-the-wild exploitation has been observed. The EPSS score is approximately 0.028%, indicating a very low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the YITH Slider for page builders plugin version 1.0.11 or earlier, using tools like WPScan or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Obtain low-privilege access: Register or use an existing low-privilege account (e.g., subscriber) on the target WordPress site.
  3. Identify unprotected endpoints: Enumerate plugin-specific AJAX actions or REST API endpoints registered by the plugin that lack proper capability checks.
  4. Send unauthorized request: Craft and send an authenticated HTTP request (with a valid nonce or session cookie) to the identified endpoint, invoking functionality normally restricted to administrators (e.g., modifying or deleting slider configurations).
  5. Achieve objective: Successfully read, modify, or delete slider data or plugin settings beyond the attacker's intended privilege level (Feedly, Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated low-privilege users (subscriber/contributor roles) making POST requests to plugin-specific AJAX endpoints (e.g., wp-admin/admin-ajax.php) with actions associated with the YITH Slider plugin outside of normal usage patterns.
  • Logs: Unexpected modifications to slider configurations or plugin settings in the WordPress database audit logs, particularly changes not initiated by administrator accounts.
  • Network: Repeated or scripted requests to WordPress AJAX or REST endpoints related to the yith-slider-for-page-builders plugin from non-administrative user sessions.

Mitigation and workarounds

Site administrators should update the YITH Slider for page builders plugin to a version beyond 1.0.11 as soon as a patched release is available from YITHEMES. In the interim, consider temporarily deactivating the plugin if it is not critical to site operations, and review user roles to minimize the number of accounts with any authenticated access. Conducting a security audit of WordPress user permissions and monitoring logs for suspicious plugin interactions is also recommended (Feedly, Patchstack).

Community reactions

The vulnerability received brief coverage from automated security news aggregators and social media accounts such as TheHackerWire on Mastodon and Bluesky shortly after disclosure. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability database listings (Feedly).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management