CVE-2025-6730 Overview
CVE-2025-6730 affects the Bonanza – WooCommerce Free Gifts Lite plugin for WordPress. The vulnerability stems from a missing capability check on the xlo_optin_call() function. Authenticated users with Subscriber-level access or higher can invoke the function and set the opt-in status to success without authorization.
The issue impacts all plugin versions up to and including 1.0.0. The flaw is classified under CWE-862 (Missing Authorization). Because the attack requires only low-privileged authentication and does not compromise confidentiality or availability, the impact is limited to unauthorized data modification.
Critical Impact
Any authenticated WordPress user can manipulate opt-in status data managed by the plugin, corrupting integrity of subscriber records.
Affected Products
- Bonanza – WooCommerce Free Gifts Lite plugin for WordPress (all versions ≤ 1.0.0)
- WordPress sites running WooCommerce with the affected plugin installed
- Any site exposing subscriber or higher user registration with this plugin active
Discovery Timeline
- 2025-07-29 - CVE-2025-6730 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-6730
Vulnerability Analysis
The vulnerability resides in the xlo_optin_call() function within the plugin's opt-in manager class. WordPress plugins expose AJAX endpoints through admin-ajax.php, and any endpoint that modifies state must verify both a nonce and the caller's capabilities. This handler omits the capability check, so WordPress authenticates the request but does not gate it by role.
Subscriber is the lowest-privileged role on most WordPress installations and is granted automatically on sites that allow open registration. An attacker holding this role can call the function and force the opt-in status to a success state. The impact is limited to integrity of opt-in tracking data; the endpoint does not expose confidential fields or destroy resources.
The root technical reference is available in the WordPress Plugin Code Review at line 244 of class-xl-opt-in-manager.php.
Root Cause
The root cause is a missing current_user_can() capability check inside the AJAX action handler bound to xlo_optin_call(). The plugin registered the handler under the authenticated hook (wp_ajax_) without restricting it to administrative roles. This design pattern violates the WordPress principle of least privilege for state-changing endpoints.
Attack Vector
The attack requires network access to the target WordPress site and valid credentials for any account at Subscriber level or higher. The attacker sends a crafted POST request to admin-ajax.php invoking the vulnerable action. No user interaction from an administrator is required, and the request can be automated across many accounts or targets.
For deeper technical detail, review the Wordfence Vulnerability Report.
Detection Methods for CVE-2025-6730
Indicators of Compromise
- POST requests to /wp-admin/admin-ajax.php with the action parameter set to the plugin's opt-in call handler, originating from Subscriber-level accounts.
- Unexpected opt-in status changes to success in plugin database tables or options without a corresponding user-initiated workflow.
- Newly created Subscriber accounts followed shortly by AJAX calls to plugin endpoints.
Detection Strategies
- Enable verbose logging on admin-ajax.php and alert on repeated invocations of plugin-specific actions by non-administrative users.
- Baseline the normal frequency of opt-in state transitions and flag anomalous bulk modifications.
- Correlate WordPress user role with the plugin actions they invoke; low-privileged users should not trigger administrative handlers.
Monitoring Recommendations
- Monitor WordPress audit logs for xlo_optin_call action invocations against the source user role.
- Track new account registrations paired with immediate AJAX activity against plugin endpoints.
- Alert on modifications to plugin-managed options and post meta associated with opt-in state.
How to Mitigate CVE-2025-6730
Immediate Actions Required
- Deactivate and remove the Bonanza – WooCommerce Free Gifts Lite plugin until a patched version is released and installed.
- Disable open user registration or restrict the default role to a minimum until the plugin is removed or updated.
- Audit existing opt-in records and reset any statuses that cannot be tied to a legitimate user action.
Patch Information
As of the latest NVD update on 2026-06-17, no fixed version beyond 1.0.0 is referenced. Site operators should monitor the Wordfence Vulnerability Report and the plugin's WordPress.org listing for a security release. Apply the vendor patch as soon as it becomes available.
Workarounds
- Restrict access to /wp-admin/admin-ajax.php for authenticated low-privileged users via a web application firewall rule targeting the vulnerable action.
- Use a WordPress security plugin to add a capability check wrapper around the xlo_optin_call action.
- Temporarily set default new-user registration to a custom role with no plugin access, or disable registration entirely.
# Example WAF rule (ModSecurity-style) to block the vulnerable action
SecRule REQUEST_URI "@endsWith /wp-admin/admin-ajax.php" \
"chain,phase:2,deny,status:403,id:1006730,\
msg:'Block CVE-2025-6730 vulnerable action'"
SecRule ARGS:action "@streq xlo_optin_call" "t:lowercase"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
