
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69298 is a Missing Authorization (Broken Access Control) vulnerability in the GhostPool Gauge WordPress theme that allows unauthenticated remote attackers to exploit incorrectly configured access control security levels. It affects all versions of the Gauge theme through 6.56.4, with no official patch available as of the latest reporting. The vulnerability was reported on November 15, 2025, and published by Patchstack on January 27, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the Gauge theme fails to perform adequate authorization checks before executing privileged or sensitive actions. This allows unauthenticated network-based attackers to invoke functionality that should be restricted to higher-privileged users, such as administrators. The attack vector is network-accessible, requires no user interaction, and has low complexity, making it straightforward to exploit at scale. The vulnerability was discovered by researcher João Pedro S Alcântara (Kinorth) and reported to Patchstack (Patchstack).
Successful exploitation allows unauthenticated attackers to perform unauthorized actions that should require elevated privileges, resulting in a high integrity impact on affected WordPress sites. Confidentiality and availability are not directly impacted per the CVSS scoring, but unauthorized modification of site content, settings, or data is possible. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity (Patchstack).
No official patch is currently available for this vulnerability, leaving all Gauge theme installations at version 6.56.4 and below exposed. The EPSS score is approximately 0.017%, indicating a relatively low but non-negligible probability of exploitation in the near term. There is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability does not appear in the CISA KEV catalog. Patchstack has issued a virtual patch (mitigation rule) to block exploitation attempts for users of their platform (Patchstack).
As of the latest reporting, no official patch has been released by GhostPool for the Gauge theme. Site owners are advised to monitor for an updated version beyond 6.56.4 and apply it immediately when available. In the interim, Patchstack has deployed a virtual patching/mitigation rule for its subscribers to block exploitation attempts. If neither option is available, site owners should consider disabling the Gauge theme or consulting their hosting provider for additional hardening measures (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering January 26 to February 1, 2026, indicating it received attention from the broader WordPress security community. Patchstack classified it as high priority and noted its potential for use in mass-exploit campaigns. No significant vendor statements from GhostPool or notable researcher commentary beyond the initial disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."