
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69297 is a Missing Authorization (Broken Access Control) vulnerability in the GhostPool Aardvark Plugin for WordPress. It affects all versions of the plugin up to and including version 2.19, allowing unauthenticated remote attackers to exploit incorrectly configured access control security levels. The vulnerability was reported on November 15, 2025, and published on January 27, 2026, with no official patch available as of the disclosure date. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing privileged actions. This allows unauthenticated network-based attackers to invoke functionality that should be restricted to higher-privileged users, with no user interaction or special conditions required. The vulnerability is categorized under OWASP Top 10 A1: Broken Access Control, and was discovered and reported by researcher João Pedro S Alcântara (Kinorth) (Patchstack).
Successful exploitation allows unauthenticated attackers to perform high-privileged actions on affected WordPress sites, resulting in a high integrity impact with no confidentiality or availability impact per the CVSS scoring. Attackers could manipulate plugin-controlled data or site configurations without any credentials, potentially defacing content, altering settings, or abusing plugin functionality in ways that undermine site integrity. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or popularity (Patchstack).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable over the network. No official patch is currently available, leaving all sites running Aardvark Plugin ≤ 2.19 exposed. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the wild, though Patchstack classifies it as high priority and expects it to be targeted in mass-exploit campaigns. No CISA KEV listing or specific threat actor attribution has been identified at this time (Patchstack).
current_user_can(), nonce, or capability checks.wp-admin/admin-ajax.php?action=<vulnerable_action> or a REST API route) with any required parameters to trigger the privileged action.wp-admin/admin-ajax.php with Aardvark Plugin-specific action parameters, or unexpected requests to plugin REST API endpoints from unknown IP addresses.No official patch from the plugin developer (GhostPool) is available as of the disclosure date; the vulnerable version remains ≤ 2.19. Site administrators are advised to deactivate and remove the Aardvark Plugin until an official fix is released. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts in the interim. If removal is not feasible, restricting access to WordPress AJAX and REST API endpoints via web application firewall (WAF) rules or server-level controls can reduce exposure (Patchstack).
Patchstack, which coordinated the disclosure, classifies this as a high-priority vulnerability and warns it is the type commonly leveraged in mass WordPress exploit campaigns. The vulnerability was credited to researcher João Pedro S Alcântara (Kinorth), who reported it on November 15, 2025. No significant vendor statement from GhostPool or broader media coverage has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."