CVE-2025-68850
7.5Codepeople · Sell Downloads
A missing authorization vulnerability in the Codepeople Sell Downloads plugin allows unauthenticated attackers to exploit incorrectly configured access control security levels.
Executive summary
The Codepeople Sell Downloads plugin contains a critical authorization flaw that permits unauthenticated access to restricted information.
Vulnerability
The plugin suffers from a missing authorization vulnerability (CWE-862) that allows unauthenticated users to bypass intended access controls. This flaw is remotely exploitable without user interaction, as indicated by the CVSS vector.
Business impact
The vulnerability allows unauthorized parties to access sensitive data protected by the Sell Downloads plugin, potentially leading to unauthorized data disclosure. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to the confidentiality of digital assets managed by the system. Failure to address this vulnerability could lead to the exposure of proprietary files or customer data, causing reputational damage and regulatory non-compliance.
Remediation
Immediate Action: Since no specific patch version is currently confirmed, administrators should immediately disable or remove the Sell Downloads plugin until the vendor releases a secure update.
Proactive Monitoring: Review web server and application access logs for unusual requests, particularly those targeting plugin-specific endpoints or directories associated with file downloads.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access attempts to plugin-specific paths, providing a layer of virtual patching.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the potential for unauthenticated data access, this vulnerability must be treated as a priority. Administrators should take immediate steps to isolate the affected plugin and monitor for any signs of unauthorized access, as the absence of a confirmed patch necessitates a proactive defensive posture to prevent potential exploitation.
More Codepeople CVEs
Sources
Originally found and disclosed by Jarno Vos (jrn5151) | Patchstack Bug Bounty Program, per the CVE Program record.