CVE-2025-14357
Awaiting Analysis Awaiting Analysis - Queue
Unauthorized Data Modification in Mega Store WooCommerce Theme

Publication date: 2026-02-19

Last updated on: 2026-02-19

Assigner: Wordfence

Description
The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the setup_widgets() function in core/includes/importer/whizzie.php in all versions up to, and including, 5.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary pages and modify site settings.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-19
Last Modified
2026-02-19
Generated
2026-06-16
AI Q&A
2026-02-19
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
misbahwp mega_store_woocommerce to 5.9 (inc)
woocommerce mega_store to 5.9 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The Mega Store Woocommerce theme for WordPress has a vulnerability due to a missing capability check in the setup_widgets() function located in core/includes/importer/whizzie.php. This flaw exists in all versions up to and including version 5.9.

Because of this missing check, authenticated users with Subscriber-level access or higher can exploit the vulnerability to create arbitrary pages and modify site settings without proper authorization.

Impact Analysis

This vulnerability allows attackers with low-level authenticated access (Subscriber-level and above) to modify site content and settings arbitrarily.

  • Creation of unauthorized pages on the website.
  • Modification of site settings without proper permissions.

Such unauthorized changes can lead to defacement, misinformation, or disruption of normal site operations.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-14357. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart