CVE-2025-68594: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68594 is a Missing Authorization vulnerability (CWE-862) in the Poll, Survey & Quiz Maker Plugin by Opinion Stage for WordPress. It allows low-privileged authenticated attackers to exploit incorrectly configured access control security levels, affecting all plugin versions up to and including 19.12.1. The vulnerability was published on December 24, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).

Technical details

The root cause is a missing authorization check (CWE-862) within the plugin's access control implementation, where certain plugin actions or endpoints fail to properly verify whether the requesting user has the required permissions. This allows any authenticated user with low privileges (e.g., a subscriber-level WordPress account) to perform actions that should be restricted to higher-privileged roles. The attack is conducted over the network with low complexity and requires no user interaction, making it straightforward to exploit once an attacker has any valid WordPress account on the target site (Feedly).

Impact

Successful exploitation results in high confidentiality and integrity impacts, with no availability impact. A low-privileged attacker could access sensitive survey, poll, and quiz data — including potentially private responses — and modify or manipulate existing plugin content without authorization. This could expose personally identifiable information collected through polls/surveys and allow unauthorized alteration of published content on the affected WordPress site (Feedly).

Exploitability

There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation as of the time of reporting. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.028%, indicating a low probability of exploitation in the near term (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Poll, Survey & Quiz Maker Plugin by Opinion Stage at version 19.12.1 or earlier using tools like WPScan or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Obtain low-privileged access: Register or obtain a low-privileged WordPress account (e.g., subscriber role) on the target site, or use existing credentials.
  3. Identify unprotected endpoints: Probe the plugin's registered REST API routes or admin-ajax actions for endpoints that lack proper capability checks, which would normally be restricted to editors or administrators.
  4. Send unauthorized requests: Craft and send HTTP requests (e.g., POST to wp-admin/admin-ajax.php or a plugin REST endpoint) with the low-privileged user's authentication cookie/nonce to access or modify poll/survey data.
  5. Achieve objective: Read private survey responses or modify poll/quiz content, potentially exfiltrating respondent data or defacing published polls (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing repeated requests to wp-admin/admin-ajax.php or plugin-specific REST API endpoints from low-privileged user accounts, particularly for actions that should require elevated permissions.
  • Logs: Authentication logs showing subscriber-level accounts performing administrative plugin operations.
  • Network: Unusual volume of requests to Opinion Stage plugin endpoints from a single authenticated session.
  • File System: Unexpected changes to poll, survey, or quiz content in the WordPress database (wp_posts or plugin-specific tables) not attributable to administrator activity.

Mitigation and workarounds

Update the Poll, Survey & Quiz Maker Plugin by Opinion Stage to a version beyond 19.12.1, which contains the fix for this vulnerability. Site administrators should also audit current WordPress user roles to ensure the principle of least privilege is applied, and review plugin access control settings. Until patching is possible, consider temporarily disabling the plugin or restricting site registration to prevent unauthorized low-privileged account creation (Feedly, Patchstack).

Community reactions

The vulnerability was reported by Patchstack and received standard coverage from vulnerability aggregation platforms. The Hacker Wire published a brief note on the CVE, and it was included in a CISA weekly vulnerability summary for the week of December 22, 2025. No notable researcher commentary or significant community discussion has been observed beyond routine disclosure (Feedly).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management