Skip to main content
Vulnerability Database/CVE-2025-66145

CVE-2025-66145: Worker for WPBakery Auth Bypass Flaw

CVE-2025-66145 is an authorization bypass vulnerability in Worker for WPBakery plugin that allows attackers to exploit misconfigured access controls. This article covers technical details, affected versions up to 1.1.1, and mitigation strategies.

Published:

CVE-2025-66145 Overview

CVE-2025-66145 is a Missing Authorization vulnerability [CWE-862] in the merkulove Worker for WPBakery WordPress plugin. The flaw affects all versions from initial release through version 1.1.1. Attackers with low-privilege authenticated access can exploit incorrectly configured access control security levels to perform actions restricted to higher-privileged users. The vulnerability impacts both integrity and availability of affected WordPress installations. Successful exploitation requires authentication but no user interaction, making it accessible to any account holder on a vulnerable site.

Critical Impact

Authenticated users with minimal privileges can bypass access controls in the Worker for WPBakery plugin, potentially modifying plugin data or triggering unauthorized operations on WordPress sites running version 1.1.1 or earlier.

Affected Products

  • merkulove Worker for WPBakery plugin — all versions through 1.1.1
  • WordPress installations with the Worker for WPBakery plugin active
  • Sites permitting low-privilege user registration alongside the vulnerable plugin

Discovery Timeline

  • 2025-12-31 - CVE-2025-66145 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66145

Vulnerability Analysis

The vulnerability stems from missing authorization checks within the Worker for WPBakery plugin. The plugin exposes functionality without validating whether the requesting user holds the required capabilities. This class of flaw, categorized under [CWE-862] Missing Authorization, occurs when code performs sensitive operations without confirming the caller's permission level.

WordPress plugins typically enforce access control through capability checks such as current_user_can() or nonce verification via check_ajax_referer(). When these checks are absent or improperly configured, any authenticated user can invoke privileged endpoints. The Patchstack advisory classifies this as a broken access control issue affecting plugin versions up to 1.1.1.

The impact scope is limited to low integrity and low availability effects with no confidentiality loss. This suggests the exploitable endpoints permit data modification or state changes rather than direct data exfiltration.

Root Cause

The root cause is incorrectly configured access control security levels within the plugin's action handlers. Handler functions execute privileged logic without verifying the requesting user's role or capability. Subscriber-level accounts inherit access intended only for administrators or editors.

Attack Vector

The attack vector is network-based and requires low-privilege authentication. An attacker registers or compromises a low-tier account on the target WordPress site. The attacker then sends crafted requests to plugin endpoints that lack proper authorization gates. No user interaction is required, and attack complexity is low. Refer to the Patchstack WordPress Vulnerability Report for technical details.

Detection Methods for CVE-2025-66145

Indicators of Compromise

  • Unexpected POST or AJAX requests to Worker for WPBakery plugin endpoints from subscriber or contributor accounts
  • Unauthorized modifications to plugin configuration, settings, or WPBakery template data
  • WordPress audit logs showing privileged actions performed by low-tier user roles
  • New or altered content associated with the Worker for WPBakery plugin outside administrative sessions

Detection Strategies

  • Monitor WordPress admin-ajax.php and REST API traffic for calls targeting Worker for WPBakery actions from non-administrative sessions
  • Deploy a web application firewall rule set that inspects requests for the plugin's action parameters and verifies expected user roles
  • Review plugin activity through WordPress audit logging solutions to identify capability mismatches

Monitoring Recommendations

  • Track version inventory across WordPress deployments to identify sites running Worker for WPBakery 1.1.1 or earlier
  • Alert on registration spikes or unusual authentication patterns preceding plugin endpoint calls
  • Correlate low-privilege user activity with configuration changes to plugin-managed assets

How to Mitigate CVE-2025-66145

Immediate Actions Required

  • Identify all WordPress installations running Worker for WPBakery version 1.1.1 or earlier
  • Restrict user registration or elevate registration approval workflows until a patch is applied
  • Temporarily deactivate the Worker for WPBakery plugin on production sites where feasible
  • Audit existing low-privilege accounts for unexpected activity against plugin endpoints

Patch Information

As of the last NVD update on 2026-06-17, no fixed version is listed for Worker for WPBakery. The advisory indicates the vulnerability affects all versions through 1.1.1. Consult the Patchstack advisory for the latest remediation guidance from the vendor.

Workarounds

  • Deactivate and remove the Worker for WPBakery plugin until an official fix is released
  • Apply virtual patching through a web application firewall to block unauthorized calls to plugin endpoints
  • Enforce role-based access restrictions using a WordPress hardening plugin that limits capabilities for subscriber and contributor roles
  • Disable open user registration on sites where the plugin remains active

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.