CVE-2025-69184
Published: 22 January 2026
Summary
CVE-2025-69184 is a high-severity Missing Authorization (CWE-862) vulnerability. Its CVSS base score is 7.3 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 21.5th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 AC-3 (Access Enforcement) and AC-14 (Permitted Actions Without Identification or Authentication).
Deeper analysis
CVE-2025-69184 is a missing authorization vulnerability (CWE-862) in the Institutions Directory WordPress plugin developed by e-plugins. The flaw enables exploitation of incorrectly configured access control security levels and affects all versions of the plugin from n/a through 1.3.4.
Remote attackers can exploit this vulnerability over the network with low attack complexity, requiring no privileges, no user interaction, and without changing scope (CVSS:3.1 score of 7.3: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). Unauthenticated adversaries may achieve limited impacts on confidentiality, integrity, and availability of the affected system.
Mitigation details are available in the Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/institutions-directory/vulnerability/wordpress-institutions-directory-plugin-1-3-4-broken-access-control-vulnerability?_s_id=cve.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-3928
Vulnerability details
Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3.4.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Missing authorization (CWE-862) in public-facing WordPress plugin directly enables remote unauthenticated exploitation of a web application.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces approved authorizations on plugin functions, blocking the unauthenticated exploitation of missing access-control checks described in CVE-2025-69184.
Requires that every Institutions Directory function be assigned only the minimum privileges needed, reducing the impact surface of the incorrectly configured access-control levels.
Explicitly identifies and limits the set of actions permitted without identification or authentication, directly addressing the unauthenticated access path exploited by the vulnerability.