5.3
CVE-2025-5813
- EPSS 0.13%
- Veröffentlicht 26.06.2025 02:22:22
- Zuletzt bearbeitet 07.07.2025 16:04:42
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Amazon Products to WooCommerce <= 1.2.7 - Missing Authorization to Unauthenticated Arbitrary Product Creation
The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to create new produces.
Mögliche Gegenmaßnahme
Amazon Products to WooCommerce: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Amazon Products to WooCommerce
Version
*-1.2.7
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Suhailahmad64 ≫ Amazon Products To Woocommerce SwPlatformwordpress Version <= 1.2.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.33 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.