CVE-2025-68565

9.8

JayBee · Twitch Player

A missing authorization vulnerability in the JayBee Twitch Player WordPress plugin allows attackers to perform unauthorized actions due to improper access control.

Executive summary

An authorization bypass vulnerability in the JayBee Twitch Player plugin may allow unauthenticated attackers to interact with restricted plugin functions.

Vulnerability

The plugin fails to perform adequate capability checks on sensitive functions, allowing unauthenticated users to trigger actions that should be restricted. This flaw is classified as a broken access control issue.

Business impact

While the technical impact is limited to partial availability or configuration issues, the lack of authorization controls exposes the site to potential configuration tampering. The 9.8 CVSS score provided is high; however, the Wordfence assessment of 5.3 suggests the risk is primarily centered on plugin-specific functionality rather than full server compromise.

Remediation

Immediate Action: As no patch is currently available, disable or deactivate the Twitch Player plugin until a secure version is released by the developer.

Proactive Monitoring: Monitor WordPress administrative logs for unauthorized plugin configuration changes or unexpected modifications to page content.

Compensating Controls: Use a Web Application Firewall (WAF) to block unauthorized access to the plugin's specific endpoints or administrative URLs.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Security teams should treat this vulnerability as a high priority due to the ease of exploitation (unauthenticated). Until the vendor releases a patched version, the safest course of action is to remove the plugin from the production environment to prevent potential access control abuse.