
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69313 is a Missing Authorization (Broken Access Control) vulnerability in the WPXPO PostX WordPress plugin (slug: ultimate-post) that allows unauthenticated remote attackers to exploit incorrectly configured access control security levels. It affects PostX versions up to and including 5.0.3, with version 5.0.4 serving as the patched release. The vulnerability was reported by researcher MD ISMAIL on October 30, 2025, and published by Patchstack on January 19, 2026, with NVD publication on January 22, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack, NVD).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning one or more plugin functions fail to perform adequate authorization checks before executing privileged or sensitive operations. This allows an unauthenticated network attacker to invoke restricted functionality — such as modifying plugin settings, accessing protected content, or triggering administrative actions — without supplying valid credentials or a nonce token. The attack vector is network-based, requires no user interaction, and has low complexity, making it trivially exploitable at scale (Patchstack, NVD).
Successful exploitation results in a high confidentiality impact, as unauthenticated attackers can access data or functionality that should be restricted to privileged users. There is no direct integrity or availability impact per the CVSS scoring, but unauthorized access to plugin functions on a WordPress site could expose sensitive configuration data, user information, or private post content. Given PostX's role as a Gutenberg block builder plugin, exploitation could also facilitate reconnaissance for further attacks against the WordPress installation (Patchstack).
No public proof-of-concept exploit code has been identified at this time, though Patchstack classifies this as a high-priority vulnerability expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-negligible probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Patchstack, NVD).
ultimate-post) version 5.0.3 or earlier using tools like WPScan, Shodan, or by checking /wp-content/plugins/ultimate-post/readme.txt for version disclosure.wp-admin/admin-ajax.php (or the relevant REST endpoint) with the target action parameter, without supplying authentication cookies or a valid nonce.wp-admin/admin-ajax.php or WordPress REST API endpoints associated with the PostX plugin (ultimate-post) from external IP addresses, particularly in high volume or automated patterns.The vendor has released PostX version 5.0.4 as the patched release, and all users should update immediately from the WordPress plugin repository. Patchstack has also issued a virtual patch (mitigation rule) for its subscribers to block exploitation attempts until the plugin update can be applied. If immediate updating is not possible, site administrators should consider temporarily deactivating the PostX plugin or restricting access to wp-admin/admin-ajax.php via firewall rules (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher MD ISMAIL, flagged it as high priority and noted that vulnerabilities of this class are commonly used in mass-exploit campaigns against WordPress sites. No significant vendor statements beyond the patch release or notable independent researcher commentary have been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."