
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68608 is a Missing Authorization (Broken Access Control) vulnerability in the DeluxeThemes Userpro WordPress plugin that allows unauthenticated attackers to exploit incorrectly configured access control security levels. It affects all versions of the Userpro plugin up to and including 5.1.9. The vulnerability was reported by Ananda Dhakal of Patchstack on May 13, 2024, and publicly disclosed on December 25, 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), corresponding to OWASP Top 10 category A1: Broken Access Control. The flaw stems from the absence of proper authorization, authentication, or nonce token checks in one or more plugin functions, allowing unauthenticated users to invoke actions that should be restricted to higher-privileged roles. No user interaction is required, and the attack is conducted entirely over the network with low complexity. No public technical write-up or proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation primarily affects integrity, as the CVSS vector indicates high integrity impact with no confidentiality or availability impact. An unauthenticated attacker could perform unauthorized privileged actions within the WordPress application — such as modifying user data or plugin settings — that should be restricted to authenticated or higher-privileged users. The vulnerability is noted as being the type used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity (Patchstack).
No public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability requires no authentication and no user interaction, making it trivially exploitable if a working exploit were developed. The EPSS score is approximately 0.039% (0.000390), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack rates its priority as "Low," assessing it as unlikely to be exploited in the near term (Patchstack).
As of the disclosure date (December 25, 2025), no official patched version of the Userpro plugin has been released by DeluxeThemes. Site administrators should update the plugin to any version released after 5.1.9 once a patch becomes available. In the interim, consider deactivating the plugin if it is not critical to site operations, restricting access to WordPress admin endpoints, and implementing a Web Application Firewall (WAF) rule — Patchstack users receive virtual patching protection automatically. Conduct an audit of user permissions and monitor for unauthorized access attempts (Patchstack).
The vulnerability was discovered and disclosed by Ananda Dhakal of Patchstack through their Vulnerability Disclosure Program (VDP). Patchstack classifies the issue as low priority, noting it is unlikely to be exploited despite the high CVSS score, and highlights the gap between CVSS scoring and real-world WordPress risk. The disclosure received routine coverage from automated vulnerability tracking services and security news aggregators (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."