CVE-2025-14361
Missing Authorization in WooCommerce Envato Affiliates
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: Patchstack
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aa-team | woocommerce_envato_affiliates | to 1.2.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Missing Authorization issue in the AA-Team Woocommerce Envato Affiliates plugin. It allows users to access functionality that is not properly restricted by Access Control Lists (ACLs), meaning that certain actions or features can be accessed without the necessary permissions.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized users performing actions or accessing features they should not be able to. According to the CVSS score, it has a high impact on integrity and a low impact on availability, which means attackers could potentially alter data or functionality within the affected system.