CVE-2025-68587
8.1Bob Watu · Watu Quiz
A missing authorization vulnerability in the Watu Quiz WordPress plugin allows authenticated users to exploit incorrectly configured access control security levels.
Executive summary
A missing authorization flaw in the Watu Quiz plugin allows authenticated attackers to bypass access controls, potentially leading to unauthorized integrity impacts.
Vulnerability
This vulnerability is a missing authorization flaw (CWE-862) that permits an authenticated user with low privileges to perform actions outside of their intended security scope. The attack vector is network-based and does not require user interaction.
Business impact
The vulnerability carries a CVSS score of 8.1, indicating a high severity risk that could lead to unauthorized modification of quiz data or settings. If exploited, an attacker could manipulate sensitive quiz configurations, potentially compromising the integrity of educational or lead-generation data managed by the plugin.
Remediation
Immediate Action: Since a specific patched version is not confirmed in the provided data, administrators should audit user permissions and restrict access to the plugin settings until an official update is released.
Proactive Monitoring: Security teams should monitor WordPress access logs for unusual administrative actions or unexpected configuration changes originating from low-privileged user accounts.
Compensating Controls: Deploy a Web Application Firewall (WAF) to filter suspicious requests targeting the plugin's administrative endpoints and enforce strict access control policies.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the high CVSS score of 8.1, this vulnerability poses a significant risk to the integrity of the affected WordPress environment. Organizations using Watu Quiz are advised to remain vigilant for vendor updates and apply them immediately upon release to remediate the underlying authorization failure.
Sources
Originally found and disclosed by daroo | Patchstack Bug Bounty Program, per the CVE Program record.