The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying a user's identity prior to logging them in through the create_user() function. This makes it possible for unauthenticated attackers to log in as administrative users.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6688.json",
"cna_assigner": "Wordfence",
"cwe_ids": [
"CWE-288"
],
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "1.3.6"
},
{
"last_affected": "2.3.8"
}
],
"source": "AFFECTED_FIELD"
}
]
}