Skip to main content
Vulnerability Database/CVE-2025-66165

CVE-2025-66165: Lottier for WPBakery Auth Bypass Flaw

CVE-2025-66165 is an authorization bypass vulnerability in the Lottier for WPBakery plugin that enables unauthorized access through misconfigured security levels. This article covers technical details, affected versions, and remediation.

Published:

CVE-2025-66165 Overview

CVE-2025-66165 is a missing authorization vulnerability in the Lottier for WPBakery WordPress plugin developed by merkulove. The flaw affects all versions of lottier-wpbakery up to and including 1.1.7. Attackers with low-privileged authenticated access can exploit incorrectly configured access control security levels to perform actions beyond their intended permission scope. The weakness is tracked under [CWE-862: Missing Authorization]. Successful exploitation impacts both confidentiality and integrity at a limited scope. The vulnerability was published to the National Vulnerability Database on December 16, 2025.

Critical Impact

Authenticated users with minimal privileges can bypass access control checks in the Lottier for WPBakery plugin, potentially modifying or accessing plugin resources reserved for higher-privileged roles.

Affected Products

  • merkulove Lottier for WPBakery plugin versions up to and including 1.1.7
  • WordPress sites running the lottier-wpbakery plugin alongside WPBakery Page Builder
  • Any WordPress deployment with authenticated low-privilege user accounts and the affected plugin installed

Discovery Timeline

  • 2025-12-16 - CVE-2025-66165 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-66165

Vulnerability Analysis

The Lottier for WPBakery plugin exposes functionality that fails to enforce authorization checks matching the intended privilege model. The plugin registers actions or endpoints accessible to authenticated users but omits capability verification tied to the sensitivity of those operations. As a result, users holding low-privilege roles such as Subscriber or Contributor can invoke functionality intended for editors or administrators. The vulnerability is classified under [CWE-862] because required authorization logic is missing rather than incorrectly implemented. Impact is bounded to the plugin's operational scope, allowing unauthorized reads and writes against plugin-managed data without affecting availability.

Root Cause

The root cause is the absence of a current_user_can() capability check or equivalent authorization gate on plugin actions. WordPress plugins must validate the acting user's role and capabilities before performing state-changing or data-exposing operations. In lottier-wpbakery through version 1.1.7, one or more handlers rely solely on authentication rather than authorization, treating any logged-in user as a legitimate caller.

Attack Vector

Exploitation requires network access to the target WordPress site and a valid authenticated session with low privileges. An attacker registers or compromises a subscriber-level account, then issues crafted requests to the vulnerable plugin endpoints. No user interaction is required from a victim. Because the attack is remote and requires only low privileges, sites permitting open user registration are at elevated risk. Refer to the Patchstack Vulnerability Report for advisory details.

Detection Methods for CVE-2025-66165

Indicators of Compromise

  • Unexpected modifications to Lottier animation configurations or WPBakery shortcode entries made by non-administrative accounts
  • Requests to admin-ajax.php or plugin-specific endpoints originating from Subscriber or Contributor user IDs
  • Newly registered low-privilege user accounts followed by activity targeting lottier-wpbakery handlers

Detection Strategies

  • Inspect WordPress access logs for POST requests to plugin action endpoints correlated with low-privilege session cookies
  • Enable WordPress audit logging plugins to record option changes, post meta updates, and AJAX invocations initiated by non-privileged users
  • Compare current plugin settings and stored animations against known-good baselines to detect unauthorized modifications

Monitoring Recommendations

  • Monitor for anomalous authentication patterns tied to newly created accounts interacting with lottier-wpbakery endpoints
  • Alert on invocations of plugin AJAX actions by user roles that should not have access to editor-level features
  • Track outbound HTTP requests from the site that could indicate secondary abuse following successful exploitation

How to Mitigate CVE-2025-66165

Immediate Actions Required

  • Identify all WordPress sites running the Lottier for WPBakery plugin at version 1.1.7 or earlier
  • Restrict new user registration or require administrator approval until a patched version is applied
  • Audit existing user accounts and revoke access for unrecognized or unnecessary low-privilege accounts
  • Review plugin-managed content and configuration for unauthorized changes since deployment

Patch Information

No fixed version is listed in the advisory at the time of publication. Consult the Patchstack Vulnerability Report for the latest vendor update status and apply any released patch immediately upon availability.

Workarounds

  • Deactivate and remove the lottier-wpbakery plugin until a patched release is available
  • Deploy a Web Application Firewall (WAF) rule to block requests to plugin endpoints from non-administrative sessions
  • Disable open user registration under Settings → General to reduce the attacker's ability to obtain a low-privilege account
  • Enforce least-privilege role assignments and remove unused accounts across the WordPress instance
bash
# Disable the vulnerable plugin via WP-CLI until a patch is released
wp plugin deactivate lottier-wpbakery
wp plugin delete lottier-wpbakery

# Disable open user registration
wp option update users_can_register 0

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.