
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68581 is a Missing Authorization vulnerability in the YITHEMES YITH Slider for page builders WordPress plugin that allows low-privilege authenticated attackers to exploit incorrectly configured access control security levels. It affects all versions of the plugin up to and including 1.0.11. The vulnerability was published on December 24, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before granting access to certain functionality. An attacker with a low-privilege WordPress account (e.g., subscriber or contributor) can send crafted network requests to access or manipulate plugin functionality that should be restricted to higher-privileged roles. No special conditions or user interaction are required beyond having a valid low-privilege account on the target WordPress site (Feedly, Patchstack).
Successful exploitation allows low-privilege authenticated attackers to bypass access controls and potentially view, modify, or delete sensitive plugin data or configurations that should be restricted to administrators. The confidentiality and integrity impacts are both rated Low, with no availability impact, meaning attackers could access or tamper with slider content and settings but are unlikely to cause service disruption. The scope is limited to the affected WordPress installation, with no direct path to lateral movement beyond the site's content management context (Feedly).
There is currently no public proof-of-concept exploit code available, and no evidence of in-the-wild exploitation has been observed. The EPSS score is approximately 0.028%, indicating a very low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
wp-admin/admin-ajax.php) with actions associated with the YITH Slider plugin outside of normal usage patterns.yith-slider-for-page-builders plugin from non-administrative user sessions.Site administrators should update the YITH Slider for page builders plugin to a version beyond 1.0.11 as soon as a patched release is available from YITHEMES. In the interim, consider temporarily deactivating the plugin if it is not critical to site operations, and review user roles to minimize the number of accounts with any authenticated access. Conducting a security audit of WordPress user permissions and monitoring logs for suspicious plugin interactions is also recommended (Feedly, Patchstack).
The vulnerability received brief coverage from automated security news aggregators and social media accounts such as TheHackerWire on Mastodon and Bluesky shortly after disclosure. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability database listings (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."