Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through <= 4.9.5.
We have discovered 900 live websites that are affected by CVE-2025-68521.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 900 live websites (85% of Wpstream install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 68 versions ( 97% of all versions) |
| 436 websites | |
| 88 websites | |
| 34 websites | |
| 28 websites | |
| 23 websites | |
| 22 websites | |
| 20 websites | |
| 17 websites | |
| 15 websites | |
| 13 websites |
| .com | 383 websites |
| .org | 148 websites |
| .de | 40 websites |
| .net | 21 websites |
| .nl | 18 websites |
| .it | 17 websites |
| .co.uk | 12 websites |
| .ru | 9 websites |
| .se | 9 websites |
| .ca | 8 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | ***,*** | ||
| *************.***.au | ***,*** | ||
| ***.rs | ***,*** | ||
| ****************.ru | ***,*** | ||
| **********.com | ***,*** | ||
| **************.com | ***,*** | ||
| ********.com | ***,*** | ||
| ******.nrw | ***,*** | ||
| ************.it | ***,*** | ||
| ****************.com | ***,*** |