CVE-2025-9286
BaseFortify
Publication date: 2025-10-03
Last updated on: 2026-04-08
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| appy_pie | connect_for_woocommerce | 1.1.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-620 | When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Appy Pie Connect for WooCommerce plugin for WordPress, where a missing authorization check in the reset_user_password() REST handler allows unauthenticated attackers to reset the passwords of arbitrary users, including administrators. This means attackers can gain administrative access without proper credentials.
How can this vulnerability impact me? :
The vulnerability can allow attackers to gain administrative access to your WordPress site by resetting passwords of any user, including administrators. This can lead to full control over the site, data breaches, unauthorized changes, and potential further exploitation.