CVE-2025-68834
Published: 20 February 2026
Summary
CVE-2025-68834 is a high-severity Missing Authorization (CWE-862) vulnerability. Its CVSS base score is 7.5 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 13.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 AC-3 (Access Enforcement) and SI-2 (Flaw Remediation).
Deeper analysis
CVE-2025-68834 is a missing authorization vulnerability (CWE-862) in the Sync Master Sheet – Product Sync with Google Sheet for WooCommerce WordPress plugin by Saiful Islam. The issue involves exploiting incorrectly configured access control security levels and affects all versions of the product-sync-master-sheet plugin from n/a through 1.1.3. Published on 2026-02-20, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), indicating high severity due to its network accessibility and lack of prerequisites.
Unauthenticated attackers can exploit this vulnerability remotely with low attack complexity and no user interaction required. Exploitation enables high-impact integrity violations, such as unauthorized modification of data, while confidentiality and availability remain unaffected.
The Patchstack advisory (https://patchstack.com/database/Wordpress/Plugin/product-sync-master-sheet/vulnerability/wordpress-sync-master-sheet-product-sync-with-google-sheet-for-woocommerce-plugin-1-1-3-broken-access-control-vulnerability?_s_id=cve) documents this broken access control issue in plugin version 1.1.3 and provides guidance for mitigation.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-207926
Vulnerability details
Missing Authorization vulnerability in Saiful Islam Sync Master Sheet – Product Sync with Google Sheet for WooCommerce product-sync-master-sheet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sync Master Sheet – Product Sync with Google Sheet for WooCommerce: from…
more
n/a through <= 1.1.3.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Missing authorization (CWE-862) in public-facing WordPress plugin directly enables remote exploitation of the application with no authentication required.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
AC-3 requires enforcement of approved authorizations for access to resources, directly addressing the missing authorization that allows unauthenticated attackers to modify data.
AC-6 least privilege restricts users and processes to only necessary access rights, mitigating the impact of incorrectly configured access control levels in the plugin.
SI-2 mandates timely identification, reporting, and correction of system flaws, enabling patching of the specific broken access control vulnerability in the WordPress plugin.