
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69023 is a Missing Authorization vulnerability in the Marketing Fire Discussion Board WordPress plugin (wp-discussion-board) that allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. It affects all versions of the plugin from n/a through 2.5.7. The vulnerability was published on December 30, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, EUVD).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before performing certain actions. The attack vector is network-based, requires low privileges (authenticated user), low attack complexity, and no user interaction. An attacker with a basic WordPress account can send crafted requests to plugin endpoints that lack proper capability checks, allowing unauthorized actions to be performed (Feedly).
Successful exploitation results in a limited integrity impact — an authenticated low-privileged attacker can perform unauthorized actions within the Discussion Board plugin, such as modifying or manipulating discussion board content or settings beyond their intended permission level. There is no confidentiality or availability impact identified. The scope is unchanged, meaning exploitation is confined to the affected plugin's context and does not directly enable lateral movement or broader system compromise (Feedly).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-69023. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly).
Users of the Discussion Board WordPress plugin by Marketing Fire should update to a version beyond 2.5.7 if a patched release is available. As an interim measure, site administrators should restrict plugin access to trusted roles only and monitor for unexpected changes to discussion board content or settings. If no patch is yet available, consider deactivating the plugin until a fix is released. Check the WordPress plugin repository or the vendor's site for the latest patched version (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."