CVE-2025-68850
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68850 is a Missing Authorization (Broken Access Control) vulnerability in the Sell Downloads WordPress plugin developed by CodePeople. It allows unauthenticated remote attackers to exploit incorrectly configured access control security levels, potentially exposing sensitive data. All versions up to and including 1.1.12 are affected; the issue was patched in version 1.2.0. The vulnerability was reported by researcher Jarno Vos (jrn5151) on October 5, 2025, published by Patchstack on December 30, 2025, and assigned a CVE on January 5, 2026. It carries a CVSS v3.1 base score of 7.5 (High), assigned by Patchstack (Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — a missing authorization, authentication, or nonce token check in one or more plugin functions that should be restricted to privileged users (Patchstack). An unauthenticated attacker can send crafted network requests to trigger these unprotected functions, bypassing WordPress capability checks and gaining access to data or actions that should require elevated privileges. No authentication or user interaction is required, and attack complexity is low, making this straightforward to exploit at scale. The vulnerability maps to OWASP Top 10 category A1: Broken Access Control (Patchstack).

Impact

Successful exploitation results in a high confidentiality impact — unauthenticated attackers can read sensitive data managed by the Sell Downloads plugin, such as customer purchase records, download links, or other protected content, without any authorization. Integrity and availability are not directly impacted according to the CVSS assessment. The scope is limited to the affected WordPress installation, but exposure of download links or customer data could have downstream consequences for site operators and their customers (Patchstack, Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-68850. The EPSS score is approximately 0.032%, indicating a low probability of exploitation in the near term (Feedly). Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity, though they rate this specific issue as low priority with no impactful threat currently observed (Patchstack). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Sell Downloads plugin (versions ≤ 1.1.12) using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files at /wp-content/plugins/sell-downloads/readme.txt.
  2. Identify unprotected endpoints: Analyze the plugin's PHP source code or use a vulnerability scanner to locate AJAX actions or REST API endpoints that lack proper current_user_can() or nonce verification checks.
  3. Craft unauthenticated request: Send an HTTP request (GET or POST) directly to the vulnerable endpoint — for example, via wp-admin/admin-ajax.php?action=<vulnerable_action> — without any authentication cookies or tokens.
  4. Extract sensitive data: Review the server response for exposed information such as download links, purchase records, or other protected plugin data that should require authorization to access (Patchstack).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to wp-admin/admin-ajax.php with Sell Downloads-specific action parameters; repeated requests from a single IP to plugin endpoints without session cookies.
  • Logs: WordPress access logs showing requests to /wp-admin/admin-ajax.php or plugin-specific REST routes from unauthenticated sources (no valid wordpress_logged_in_* cookie); high-frequency automated scanning patterns targeting the plugin.
  • File System: No file-system artifacts are expected for this read-only access control bypass, but monitor for unexpected file creation in /wp-content/plugins/sell-downloads/ that could indicate follow-on activity.

Mitigation and workarounds

The vendor (CodePeople) has released a patched version: Sell Downloads 1.2.0. Site administrators should update the plugin immediately via the WordPress dashboard or by downloading the latest version from the WordPress plugin repository. If an immediate update is not possible, consider temporarily deactivating the plugin or using a Web Application Firewall (WAF) rule — Patchstack users can enable virtual patching for automatic protection. No other configuration-based workarounds have been documented (Patchstack).

Community reactions

The vulnerability received limited but standard community coverage upon publication. TheHackerWire shared the CVE details on Infosec.Exchange and Bluesky shortly after disclosure, and it was included in CISA's weekly vulnerability bulletin for the week of January 5, 2026. Patchstack, the reporting CNA, characterized the issue as low priority with no impactful threat currently observed, tempering concern in the security community (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management