CVE-2025-68860: WordPress Mobile builder plugin <= 1.4.2 - Broken Authentication vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder allows Authentication Abuse.This issue affects Mobile builder: from n/a through 1.4.2.
Other sources
Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder mobile-builder allows Authentication Abuse.This issue affects Mobile builder: from n/a through <= 1.4.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68860?
CVE-2025-68860 is considered a high-severity vulnerability due to authentication bypass risks.
How do I fix CVE-2025-68860?
To fix CVE-2025-68860, update Mobile Builder to the latest version beyond 1.4.2.
What version of Mobile Builder is affected by CVE-2025-68860?
CVE-2025-68860 affects Mobile Builder from n/a up to version 1.4.2.
What type of vulnerability is CVE-2025-68860?
CVE-2025-68860 is classified as an Authentication Bypass vulnerability.
Can CVE-2025-68860 lead to unauthorized access?
Yes, CVE-2025-68860 can allow attackers to gain unauthorized access to the Mobile Builder application.