
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69293 is an Incorrect Privilege Assignment vulnerability in the e-plugins "Final User" WordPress plugin that allows authenticated attackers with low-level privileges to escalate their privileges to gain higher-level access. It affects all versions of the plugin through 1.2.5. The vulnerability was reported by researcher Phat RiO on November 13, 2025, and publicly disclosed by Patchstack on January 22, 2026. It carries a CVSS v3.1 base score of 8.8 (High), assessed by CISA-ADP (Patchstack, NVD).
The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the plugin incorrectly assigns or validates privilege levels during certain operations, allowing a low-privileged user (e.g., a Subscriber-level account) to elevate their role to one with higher permissions. The attack vector is network-based, requires low privileges, no user interaction, and low attack complexity, making it straightforward to exploit for any authenticated WordPress user. The vulnerability was mapped to OWASP Top 10 category A7: Identification and Authentication Failures (Patchstack).
Successful exploitation allows a low-privileged authenticated attacker (e.g., a Subscriber) to escalate their account to a higher-privileged role, potentially gaining full administrative control of the affected WordPress site. This could result in unauthorized access to sensitive data, modification of site content and configurations, installation of malicious plugins or backdoors, and complete site takeover. The high confidentiality, integrity, and availability impact scores reflect the potential for total compromise of the WordPress installation (Patchstack).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.017%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
/wp-content/plugins/final-user/readme.txt.wp_usermeta table with wp_capabilities modified to administrator).As of the disclosure date, no official patch from the plugin developer (e-plugins) is available for the Final User plugin. Site administrators should immediately deactivate and remove the Final User plugin until a patched version (greater than 1.2.5) is released. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts in the interim. Additionally, administrators should restrict user registration on their WordPress sites if not required, and implement network-level access controls to limit exposure (Patchstack).
Wordfence included CVE-2025-69293 in its weekly WordPress vulnerability report for the period of January 19–25, 2026, highlighting it as part of a broader set of plugin vulnerabilities disclosed that week. Patchstack, which discovered and reported the vulnerability, classified it as high priority and noted the risk of mass-exploit campaigns targeting WordPress sites. No significant additional vendor statements or notable researcher commentary beyond the initial disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."