
WordPress Mobile builder Plugin <= 1.4.2 is vulnerable to a high priority Broken Authentication
WordPress Mobile builder Plugin <= 1.4.2 is vulnerable to a high priority Broken Authentication
WordPress Mobile builder Plugin versions <= 1.4.2 are vulnerable to a high priority Broken Authentication issue.
CVE: CVE-2025-68860
Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder allows Authentication Abuse. This issue affects Mobile builder from n/a through 1.4.2.
A remote attacker can craft a valid authentication token and gain administrator access without any prior interaction or credentials, leading to full compromise of the WordPress installation.
CVE-2025-68860.py is a fully automated exploit for the WordPress Mobile builder <= 1.4.2 Authentication Bypass vulnerability.
On execution, the script:
user_id=1) with a known static secret./wp-json/wp/v2/users/me endpoint to confirm administrator access.Nxploitedadmin[email protected]CVE-2025-68860.py
python3 CVE-2025-68860.py
pyjwtrequestscoloramapip3 install pyjwt requests colorama
Upon execution and successful exploitation, you will get:
Username : Nxploited
Password : admin
Email : [email protected]
This script is provided for educational and authorized testing purposes only.
Do not use it against systems you do not own or have explicit, legal authorization to test.
Any misuse may be illegal and is solely the user’s responsibility.
By: Nxploited (Khaled Alenazi)
Telegram: @KNxploited
GitHub: https://github.com/Nxploited