CVE-2025-11237
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-11

Last updated on: 2025-11-12

Assigner: WPScan

Description
The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-11
Last Modified
2025-11-12
Generated
2026-05-07
AI Q&A
2025-11-11
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
wordpress wordpress *
make_email_customizer woocommerce *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The vulnerability in the Make Email Customizer for WooCommerce WordPress plugin (up to version 1.0.6) is due to missing proper authorization checks and option validation in its AJAX actions. This flaw allows any authenticated user, including low-privileged roles like Subscribers, to update arbitrary WordPress options, which they normally should not be able to modify.


How can this vulnerability impact me? :

This vulnerability can allow unauthorized users with minimal privileges to change WordPress settings, potentially leading to site misconfiguration, security bypass, or other malicious actions that compromise the integrity and security of the WordPress site.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart