CVE-2025-68608: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68608 is a Missing Authorization (Broken Access Control) vulnerability in the DeluxeThemes Userpro WordPress plugin that allows unauthenticated attackers to exploit incorrectly configured access control security levels. It affects all versions of the Userpro plugin up to and including 5.1.9. The vulnerability was reported by Ananda Dhakal of Patchstack on May 13, 2024, and publicly disclosed on December 25, 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), corresponding to OWASP Top 10 category A1: Broken Access Control. The flaw stems from the absence of proper authorization, authentication, or nonce token checks in one or more plugin functions, allowing unauthenticated users to invoke actions that should be restricted to higher-privileged roles. No user interaction is required, and the attack is conducted entirely over the network with low complexity. No public technical write-up or proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation primarily affects integrity, as the CVSS vector indicates high integrity impact with no confidentiality or availability impact. An unauthenticated attacker could perform unauthorized privileged actions within the WordPress application — such as modifying user data or plugin settings — that should be restricted to authenticated or higher-privileged users. The vulnerability is noted as being the type used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity (Patchstack).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability requires no authentication and no user interaction, making it trivially exploitable if a working exploit were developed. The EPSS score is approximately 0.039% (0.000390), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack rates its priority as "Low," assessing it as unlikely to be exploited in the near term (Patchstack).

Mitigation and workarounds

As of the disclosure date (December 25, 2025), no official patched version of the Userpro plugin has been released by DeluxeThemes. Site administrators should update the plugin to any version released after 5.1.9 once a patch becomes available. In the interim, consider deactivating the plugin if it is not critical to site operations, restricting access to WordPress admin endpoints, and implementing a Web Application Firewall (WAF) rule — Patchstack users receive virtual patching protection automatically. Conduct an audit of user permissions and monitor for unauthorized access attempts (Patchstack).

Community reactions

The vulnerability was discovered and disclosed by Ananda Dhakal of Patchstack through their Vulnerability Disclosure Program (VDP). Patchstack classifies the issue as low priority, noting it is unlikely to be exploited despite the high CVSS score, and highlights the gap between CVSS scoring and real-world WordPress risk. The disclosure received routine coverage from automated vulnerability tracking services and security news aggregators (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management