CVE-2025-68571
8.8SALESmanago · SALESmanago & Leadoo
A missing authorization vulnerability in the SALESmanago and Leadoo plugin allows unauthenticated attackers to exploit incorrectly configured access control security levels.
Executive summary
A critical missing authorization flaw in the SALESmanago and Leadoo plugin exposes systems to unauthorized access due to improper access control configurations.
Vulnerability
This is a missing authorization vulnerability (CWE-862) triggered by the lack of proper capability checks in the plugin, allowing unauthenticated remote attackers to manipulate access control settings.
Business impact
The exploitation of this vulnerability permits unauthorized modification of access control levels, which may lead to privilege escalation or unauthorized data exposure. Given the CVSS score of 8.8, this represents a significant security risk that could compromise the integrity of the entire WordPress environment and the sensitive marketing data managed by the platform.
Remediation
Immediate Action: Update the SALESmanago and Leadoo plugin to a version beyond 3.9.0 as soon as the vendor provides a patch, or deactivate the plugin if immediate updates are unavailable.
Proactive Monitoring: Review system access logs for unusual administrative activity or unexpected changes to user role configurations.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized requests to the plugin's administrative endpoints.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
The vulnerability poses a high risk to organizational security due to the lack of required authentication for sensitive access control operations. Administrators should prioritize monitoring for any unauthorized configuration changes and ensure the plugin is updated immediately upon the release of a security fix from the vendor.
More SALESmanago CVEs
Sources
Originally found and disclosed by Legion Hunter | Patchstack Bug Bounty Program, per the CVE Program record.