
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69394 is an Authorization Bypass Through User-Controlled Key (IDOR) vulnerability in the Cnvrse WordPress plugin by cnvrse. It allows unauthenticated remote attackers to access sensitive information by exploiting incorrectly configured access control security levels. The vulnerability affects Cnvrse versions from n/a through versions prior to 026.02.10.20. It carries a CVSS v3.1 base score of 7.5 (High), with high confidentiality impact and no authentication required (Feedly).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), commonly known as an Insecure Direct Object Reference (IDOR). An attacker can manipulate user-controlled keys or identifiers in requests to bypass access controls and retrieve resources belonging to other users or privileged contexts. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable against any exposed instance of the plugin (Feedly).
Successful exploitation results in unauthorized access to sensitive data protected by the plugin's access controls, with a high confidentiality impact. Integrity and availability are not directly affected by this vulnerability. Depending on the data managed by the Cnvrse plugin, exposed information could include user data, private content, or configuration details stored within the WordPress installation (Feedly).
The vulnerability requires no authentication and no user interaction, making it accessible to any remote attacker. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of active exploitation in the wild. No public proof-of-concept exploit code, exploit kit integration, threat actor attribution, or CISA KEV catalog listing has been identified for this CVE at this time (Feedly).
/wp-content/plugins/cnvrse/) with varying ID values and no associated authenticated session cookies.Users should update the Cnvrse plugin to version 026.02.10.20 or later, which addresses the access control misconfiguration. Until patching is possible, consider disabling the plugin on publicly accessible WordPress installations or restricting access to the WordPress site via IP allowlisting. Regularly audit WordPress plugin versions and apply updates promptly to minimize exposure (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."