CVE-2025-68980
8.1designthemes · WeDesignTech Portfolio
The WeDesignTech Portfolio plugin for WordPress is vulnerable to a missing authorization flaw, allowing unauthenticated attackers to perform unauthorized actions due to incorrect access control.
Executive summary
The WeDesignTech Portfolio plugin contains a missing authorization vulnerability that allows unauthenticated attackers to bypass access controls and potentially modify site data.
Vulnerability
This is a missing authorization vulnerability (CWE-862) occurring within the plugin. The vulnerability allows unauthenticated attackers to interact with restricted functions because the software fails to perform proper capability checks before executing sensitive actions.
Business impact
The vulnerability carries a CVSS score of 8.1, indicating a high severity risk. Successful exploitation could allow unauthorized individuals to modify plugin settings or data, leading to potential site integrity loss or unauthorized information disclosure. Given the plugin's role in portfolio management, this could result in reputational damage and the loss of visitor trust.
Remediation
Immediate Action: Since a specific patch version is not currently identified, users should disable or remove the WeDesignTech Portfolio plugin until the vendor releases a secure version.
Proactive Monitoring: Security teams should review server access logs for unusual POST requests originating from unauthenticated sessions targeting the plugin’s directory or associated endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized requests to the plugin's specific administrative or data-handling endpoints.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the high CVSS score and the ability for unauthenticated attackers to bypass security controls, this vulnerability poses a significant risk to site integrity. Organizations currently using the WeDesignTech Portfolio plugin are strongly advised to deactivate the software immediately and monitor vendor communication channels for the release of a patched version.
More designthemes CVEs
Sources
Originally found and disclosed by Phat RiO | Patchstack Bug Bounty Program, per the CVE Program record.