CVE-2025-11237
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-12
Assigner: WPScan
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpress | wordpress | * |
| make_email_customizer | woocommerce | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in the Make Email Customizer for WooCommerce WordPress plugin (up to version 1.0.6) is due to missing proper authorization checks and option validation in its AJAX actions. This flaw allows any authenticated user, including low-privileged roles like Subscribers, to update arbitrary WordPress options, which they normally should not be able to modify.
How can this vulnerability impact me? :
This vulnerability can allow unauthorized users with minimal privileges to change WordPress settings, potentially leading to site misconfiguration, security bypass, or other malicious actions that compromise the integrity and security of the WordPress site.