
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68850 is a Missing Authorization (Broken Access Control) vulnerability in the Sell Downloads WordPress plugin developed by CodePeople. It allows unauthenticated remote attackers to exploit incorrectly configured access control security levels, potentially exposing sensitive data. All versions up to and including 1.1.12 are affected; the issue was patched in version 1.2.0. The vulnerability was reported by researcher Jarno Vos (jrn5151) on October 5, 2025, published by Patchstack on December 30, 2025, and assigned a CVE on January 5, 2026. It carries a CVSS v3.1 base score of 7.5 (High), assigned by Patchstack (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization) — a missing authorization, authentication, or nonce token check in one or more plugin functions that should be restricted to privileged users (Patchstack). An unauthenticated attacker can send crafted network requests to trigger these unprotected functions, bypassing WordPress capability checks and gaining access to data or actions that should require elevated privileges. No authentication or user interaction is required, and attack complexity is low, making this straightforward to exploit at scale. The vulnerability maps to OWASP Top 10 category A1: Broken Access Control (Patchstack).
Successful exploitation results in a high confidentiality impact — unauthenticated attackers can read sensitive data managed by the Sell Downloads plugin, such as customer purchase records, download links, or other protected content, without any authorization. Integrity and availability are not directly impacted according to the CVSS assessment. The scope is limited to the affected WordPress installation, but exposure of download links or customer data could have downstream consequences for site operators and their customers (Patchstack, Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-68850. The EPSS score is approximately 0.032%, indicating a low probability of exploitation in the near term (Feedly). Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity, though they rate this specific issue as low priority with no impactful threat currently observed (Patchstack). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
readme.txt files at /wp-content/plugins/sell-downloads/readme.txt.current_user_can() or nonce verification checks.wp-admin/admin-ajax.php?action=<vulnerable_action> — without any authentication cookies or tokens.wp-admin/admin-ajax.php with Sell Downloads-specific action parameters; repeated requests from a single IP to plugin endpoints without session cookies./wp-admin/admin-ajax.php or plugin-specific REST routes from unauthenticated sources (no valid wordpress_logged_in_* cookie); high-frequency automated scanning patterns targeting the plugin./wp-content/plugins/sell-downloads/ that could indicate follow-on activity.The vendor (CodePeople) has released a patched version: Sell Downloads 1.2.0. Site administrators should update the plugin immediately via the WordPress dashboard or by downloading the latest version from the WordPress plugin repository. If an immediate update is not possible, consider temporarily deactivating the plugin or using a Web Application Firewall (WAF) rule — Patchstack users can enable virtual patching for automatic protection. No other configuration-based workarounds have been documented (Patchstack).
The vulnerability received limited but standard community coverage upon publication. TheHackerWire shared the CVE details on Infosec.Exchange and Bluesky shortly after disclosure, and it was included in CISA's weekly vulnerability bulletin for the week of January 5, 2026. Patchstack, the reporting CNA, characterized the issue as low priority with no impactful threat currently observed, tempering concern in the security community (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."