Junglewise Threat Intelligence

CVE-2025-68049: bunny.net WordPress plugin broken access control

CVE-2025-68049 · Severity: medium · CVSS 6.3 · Published 2026-06-15

Executive brief

The bunny.net plugin for WordPress, which helps websites deliver content faster via a CDN, contains a security flaw that allows low-level users to perform actions they should not be authorized to do. An attacker with a basic 'Subscriber' account could potentially modify settings or access restricted functions, leading to unauthorized changes to the website's configuration. This could disrupt site operations or lead to further security compromises if not addressed.

Technical details

The bunny.net plugin for WordPress (versions 2.3.6 and below) suffers from a broken access control vulnerability (CWE-862: Missing Authorization). The flaw exists because the plugin fails to properly validate user permissions or implement sufficient nonce checks on certain functions. An attacker authenticated with low-level 'Subscriber' privileges can exploit this over the network to execute higher-privileged actions. This could result in unauthorized configuration changes or data manipulation. The issue is resolved in version 2.3.7.

Affected products

  • bunny.net bunny.net <= 2.3.6

Timeline

  • 2025-11-16: other: Reported by NumeX
  • 2026-05-07: advisory: Patchstack advisory published
  • 2026-05-07: patched: Version 2.3.7 released
  • 2026-06-15: disclosed: NVD publication date

References