๐Ÿ” CVE Alert

CVE-2025-68895

MEDIUM 6.5

WordPress AhaChat Messenger Marketing plugin <= 1.1 - Broken Authentication vulnerability

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Authentication Bypass Using an Alternate Path or Channel vulnerability in ahachat AhaChat Messenger Marketing ahachat-messenger-marketing allows Password Recovery Exploitation.This issue affects AhaChat Messenger Marketing: from n/a through <= 1.1.

CWE CWE-288
Vendor ahachat
Product ahachat messenger marketing
Published Feb 20, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for ahachat ahachat messenger marketing

Be the first to know when new medium vulnerabilities affecting ahachat ahachat messenger marketing are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ahachat / AhaChat Messenger Marketing
0 โ‰ค 1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/ahachat-messenger-marketing/vulnerability/wordpress-ahachat-messenger-marketing-plugin-1-1-broken-authentication-vulnerability?_s_id=cve

Credits

Rapid0nion | Patchstack Bug Bounty Program