CVE-2025-69378
Privilege Escalation via Incorrect Privilege Assignment in XforWooCommerce Filter
Publication date: 2026-02-20
Last updated on: 2026-04-27
Assigner: Patchstack
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| patchstack | product_filter_for_woocommerce | to 9.1.2 (inc) |
| prdctfltr | product_filter_for_woocommerce | to 9.1.2 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability be detected on my network or system? Can you suggest some commands?
There is no specific information provided about commands or methods to detect this vulnerability on your network or system.
Can you explain this vulnerability to me?
CVE-2025-69378 is a medium priority privilege escalation vulnerability in the WordPress Product Filter for WooCommerce Plugin versions up to and including 9.1.2.
This vulnerability allows a malicious user with low-level privileges, such as a Shop Manager, to escalate their privileges to a higher level, potentially gaining full control over the affected website.
It is classified under OWASP Top 10 A7: Identification and Authentication Failures.
How can this vulnerability impact me? :
If exploited, this vulnerability can allow an attacker with limited access to escalate their privileges and gain full control over the affected WooCommerce website.
This could lead to unauthorized changes, data manipulation, or other malicious activities on the website.
Since no official patch is currently available, the risk remains until mitigations are applied.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
I don't know
What immediate steps should I take to mitigate this vulnerability?
Since no official patch is currently available for this vulnerability, it is recommended to apply the mitigation rule issued by Patchstack immediately.
This mitigation rule can block attacks exploiting the privilege escalation vulnerability in the Product Filter for WooCommerce plugin versions up to 9.1.2.
Implementing this mitigation helps maintain website security by automatically blocking exploit attempts until an official patch is released.