CVE-2025-68578
8.1Addonify · addonify-quick-view
A missing authorization vulnerability in the Addonify addonify-quick-view plugin allows unauthenticated attackers to exploit incorrectly configured access controls.
Executive summary
The Addonify addonify-quick-view plugin contains a critical missing authorization vulnerability that allows unauthenticated access to restricted functions.
Vulnerability
This flaw is classified as a missing authorization vulnerability (CWE-862) occurring within the addonify-quick-view plugin. The vulnerability allows unauthenticated attackers to perform unauthorized actions due to improper access control security levels.
Business impact
The exploitation of this vulnerability could lead to unauthorized modifications or access to site functions, potentially resulting in data manipulation or service disruption. With a CVSS score of 8.1, the vulnerability is classified as high severity, reflecting the significant risk posed by the lack of authentication requirements for the affected endpoints.
Remediation
Immediate Action: Because a specific patch version is currently unknown, administrators should immediately deactivate or uninstall the addonify-quick-view plugin until a secure update is released by the vendor.
Proactive Monitoring: Review web server and application access logs for suspicious requests originating from unauthorized IP addresses, specifically targeting quick-view functionality.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to block unauthorized access to the plugin-specific endpoints associated with the quick-view feature.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the potential for unauthenticated access, this vulnerability presents a significant security risk to WordPress installations. Organizations should prioritize the removal of the vulnerable plugin until the vendor provides a verified security update, as the current lack of authorization checks leaves the application susceptible to unauthorized interaction.
Sources
Originally found and disclosed by Legion Hunter | Patchstack Bug Bounty Program, per the CVE Program record.