CVE-2025-68850

7.5

Codepeople · Sell Downloads

A missing authorization vulnerability in the Codepeople Sell Downloads plugin allows unauthenticated attackers to exploit incorrectly configured access control security levels.

Executive summary

The Codepeople Sell Downloads plugin contains a critical authorization flaw that permits unauthenticated access to restricted information.

Vulnerability

The plugin suffers from a missing authorization vulnerability (CWE-862) that allows unauthenticated users to bypass intended access controls. This flaw is remotely exploitable without user interaction, as indicated by the CVSS vector.

Business impact

The vulnerability allows unauthorized parties to access sensitive data protected by the Sell Downloads plugin, potentially leading to unauthorized data disclosure. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to the confidentiality of digital assets managed by the system. Failure to address this vulnerability could lead to the exposure of proprietary files or customer data, causing reputational damage and regulatory non-compliance.

Remediation

Immediate Action: Since no specific patch version is currently confirmed, administrators should immediately disable or remove the Sell Downloads plugin until the vendor releases a secure update.

Proactive Monitoring: Review web server and application access logs for unusual requests, particularly those targeting plugin-specific endpoints or directories associated with file downloads.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access attempts to plugin-specific paths, providing a layer of virtual patching.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the potential for unauthenticated data access, this vulnerability must be treated as a priority. Administrators should take immediate steps to isolate the affected plugin and monitor for any signs of unauthorized access, as the absence of a confirmed patch necessitates a proactive defensive posture to prevent potential exploitation.

More Codepeople CVEs

Sources

Originally found and disclosed by Jarno Vos (jrn5151) | Patchstack Bug Bounty Program, per the CVE Program record.