VYPR
Medium severity6.5NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026

CVE-2025-68026

CVE-2025-68026

Description

Missing Authorization vulnerability in Niaj Morshed LC Wizard ghl-wizard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LC Wizard: from n/a through <= 2.1.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The LC Wizard WordPress plugin through v2.1.1 has a missing authorization vulnerability allowing unauthenticated settings changes, which can be exploited in mass campaigns.

Overview

The LC Wizard plugin for WordPress (ghl-wizard) contains a Missing Authorization vulnerability (CVE-2025-68026) in versions up to and including 2.1.1. This flaw stems from incorrectly configured access control security levels, enabling unauthenticated attackers to modify plugin settings without proper permission checks [1].

Exploitation

The vulnerability is a settings change issue that requires no authentication, making it accessible to any unauthenticated remote attacker. According to Patchstack, this type of vulnerability is moderately dangerous and expected to become exploited in mass campaigns targeting thousands of websites regardless of traffic size [1]. The attack surface is the plugin's settings endpoint, which does not enforce authorization.

Impact

Successful exploitation allows an attacker to alter critical plugin configurations. This could lead to unauthorized changes that affect the functionality of the LC Wizard, potentially enabling further compromise such as redirection, data exfiltration, or privilege escalation within WordPress. The broad accessibility increases the risk of widespread automated attacks.

Mitigation

The vendor has released version 2.1.2 which fixes the vulnerability. All users are strongly advised to update immediately [1]. For those unable to update, Patchstack offers a mitigation rule that blocks attacks until the patch is applied. Administrators should also consider enabling auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.