
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68895 is an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288) in the AhaChat Messenger Marketing WordPress plugin by ahachat. The flaw allows unauthenticated remote attackers to exploit the password recovery mechanism to bypass authentication. All versions up to and including 1.1 are affected. It carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, Wordfence).
The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and is specifically categorized as a Password Recovery Exploitation issue. An unauthenticated attacker can abuse an alternate authentication path — likely a flawed password reset or recovery flow — to bypass normal login controls without requiring any prior credentials or user interaction. The attack is network-based, requires low complexity, and no privileges are needed to trigger it (Feedly, Wordfence).
Successful exploitation results in limited but meaningful impacts to integrity and availability, with no direct confidentiality impact per the CVSS scoring. An attacker could manipulate plugin functionality or disrupt availability of the AhaChat Messenger Marketing features on the affected WordPress site. While the scope is unchanged and lateral movement potential is limited, the unauthenticated nature of the attack lowers the barrier for mass exploitation against WordPress sites running the vulnerable plugin (Feedly).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-68895 at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.024%, indicating a low probability of exploitation in the near term (Feedly).
Users should update the AhaChat Messenger Marketing WordPress plugin to a version beyond 1.1 if a patched release is available from the plugin vendor or the WordPress plugin repository. If no patched version is yet available, administrators should consider deactivating and removing the plugin until a fix is released. Restricting access to WordPress admin and plugin endpoints via firewall rules or web application firewall (WAF) rules can serve as an interim mitigation (Feedly, Wordfence).
Wordfence included CVE-2025-68895 in their weekly WordPress vulnerability report covering January 26 – February 1, 2026, highlighting it as part of a broader set of WordPress plugin authentication issues (Wordfence). No significant additional vendor statements or notable researcher commentary have been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."