CVE-2025-68026
Description
Missing Authorization vulnerability in Niaj Morshed LC Wizard ghl-wizard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LC Wizard: from n/a through <= 2.1.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The LC Wizard WordPress plugin through v2.1.1 has a missing authorization vulnerability allowing unauthenticated settings changes, which can be exploited in mass campaigns.
Overview
The LC Wizard plugin for WordPress (ghl-wizard) contains a Missing Authorization vulnerability (CVE-2025-68026) in versions up to and including 2.1.1. This flaw stems from incorrectly configured access control security levels, enabling unauthenticated attackers to modify plugin settings without proper permission checks [1].
Exploitation
The vulnerability is a settings change issue that requires no authentication, making it accessible to any unauthenticated remote attacker. According to Patchstack, this type of vulnerability is moderately dangerous and expected to become exploited in mass campaigns targeting thousands of websites regardless of traffic size [1]. The attack surface is the plugin's settings endpoint, which does not enforce authorization.
Impact
Successful exploitation allows an attacker to alter critical plugin configurations. This could lead to unauthorized changes that affect the functionality of the LC Wizard, potentially enabling further compromise such as redirection, data exfiltration, or privilege escalation within WordPress. The broad accessibility increases the risk of widespread automated attacks.
Mitigation
The vendor has released version 2.1.2 which fixes the vulnerability. All users are strongly advised to update immediately [1]. For those unable to update, Patchstack offers a mitigation rule that blocks attacks until the patch is applied. Administrators should also consider enabling auto-updates for vulnerable plugins [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.