Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-69394
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-69394 is an Authorization Bypass Through User-Controlled Key (IDOR) vulnerability in the Cnvrse WordPress plugin by cnvrse. It allows unauthenticated remote attackers to access sensitive information by exploiting incorrectly configured access control security levels. The vulnerability affects Cnvrse versions from n/a through versions prior to 026.02.10.20. It carries a CVSS v3.1 base score of 7.5 (High), with high confidentiality impact and no authentication required (Feedly).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), commonly known as an Insecure Direct Object Reference (IDOR). An attacker can manipulate user-controlled keys or identifiers in requests to bypass access controls and retrieve resources belonging to other users or privileged contexts. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable against any exposed instance of the plugin (Feedly).

Impact

Successful exploitation results in unauthorized access to sensitive data protected by the plugin's access controls, with a high confidentiality impact. Integrity and availability are not directly affected by this vulnerability. Depending on the data managed by the Cnvrse plugin, exposed information could include user data, private content, or configuration details stored within the WordPress installation (Feedly).

Exploitability

The vulnerability requires no authentication and no user interaction, making it accessible to any remote attacker. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of active exploitation in the wild. No public proof-of-concept exploit code, exploit kit integration, threat actor attribution, or CISA KEV catalog listing has been identified for this CVE at this time (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Cnvrse plugin (versions prior to 026.02.10.20) using tools like WPScan, Shodan, or Google dorks targeting plugin-specific file paths.
  2. Enumerate object identifiers: Observe or guess user-controlled keys (e.g., numeric IDs, UUIDs) used in plugin API requests or URL parameters that reference protected resources.
  3. Craft malicious request: Send unauthenticated HTTP requests to the vulnerable plugin endpoint, substituting the object identifier with values belonging to other users or privileged resources.
  4. Extract sensitive data: Review the server's response for unauthorized data disclosure, such as private user records, restricted content, or configuration details managed by the plugin (Feedly).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP GET or POST requests to Cnvrse plugin endpoints with sequential or enumerated object ID parameters from a single IP address.
  • Logs: WordPress access logs showing repeated requests to plugin-specific URLs (e.g., paths under /wp-content/plugins/cnvrse/) with varying ID values and no associated authenticated session cookies.
  • Logs: HTTP 200 responses to requests that should require authentication, particularly for resource retrieval endpoints of the Cnvrse plugin.

Mitigation and workarounds

Users should update the Cnvrse plugin to version 026.02.10.20 or later, which addresses the access control misconfiguration. Until patching is possible, consider disabling the plugin on publicly accessible WordPress installations or restricting access to the WordPress site via IP allowlisting. Regularly audit WordPress plugin versions and apply updates promptly to minimize exposure (Feedly).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88788MEDIUM6.8
  • text-styler
NoNoSep 19, 2026
CVE-2026-9858MEDIUM4.3
  • wc-partial-shipment
NoYesSep 19, 2026
CVE-2026-9766MEDIUM4.3
  • empik-for-woocommerce
NoYesSep 19, 2026
CVE-2026-9613MEDIUM4.3
  • datalogics
NoYesSep 19, 2026
CVE-2026-87848LOW3.7
  • mpcx-lightbox
NoNoSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management